Percovision Data Breach: 106,515 Bulgarian User Records Exposed
106,515 User Records Exposed in Percovision Bulgarian Platform Breach
In August 2018, Percovision -- a Bulgarian platform at percovision.info -- suffered a data breach exposing 106,515 records containing email addresses and PHPass-hashed passwords. PHPass is a PHP-based password hashing framework once common in WordPress and similar content management systems. While it provides more protection than MD5, it is consideraby weaker than modern alternatives like bcrypt and Argon2, and passwords hashed with PHPass can be cracked with significatly less computational effort than truly strong hashing schemes require.
Percovision Data Breach: Breach Summary
- Records Exposed: 106,515
- Data Types: Email addresses, password hashes (PHPass)
- Breach Type: Database breach
- Country Affected: Bulgaria
- Date Leaked: August 2018
PHPass: Better Than MD5, But Still Outdated
PHPass was a reasonable password hashing choice for its era -- it was widely adopted in PHP applications from the early 2000s onward and provided meaningful protection compared to raw MD5 or SHA1. But security standards have continued advancing, and PHPass is now considered inadequate by modern cryptographic guidelines. It lacks the configurable memory-hardness of Argon2, and its work factor is lower than what current hardware requires to present a real obstacle to offline cracking. For the 106,515 users affected by the Percovision breach, this means their passwords have moderate but not strong protection. Anyone who used a common password or a password also used on other platforms should act as though it is compromised.
Why Regional Platform Breaches Matter Globally
Data breaches don't respect borders. A user in any country who signed up for a Bulgarian platform with their primary email and a reused password is just as vulnerable to credential stuffing as someone affected by a breach of a global service. The Percovision breach is part of a pattern of smaller, less publicized breaches that feed acumulatively into the same criminal credential markets as major incidents. The 106,515 email addresses exposed here join the broader pool of identities available to attackers, each one a potentialy valid key to other accounts where the same email-password combination was reused.
Find Out if Your Email Was in the Percovision Breach
HEROIC's free breach scanner searches across more than 400 billion exposed records, including smaller regional platform breaches like Percovision. Enter your email to see if your credentials appear in this or any other known breach database. Early awareness is the most valueable tool you have for preventing credential stuffing attacks from succeeding against your other accounts.
Breach Breakdown
106,515 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds