SBoards Database Contains 127,686 Email and Plaintext Password Records
HEROIC analysts discovered the SBoards breach while reviewing older datasets that have been recirculated through public aggregation services. The breach occured in August 2018, when the database of SBoards, a now-defunct U.S.-based informational website, was compromised. A total of 127,686 user records were exposed. What makes this breach particularly serious is that passwords were stored and leaked in plaintext, meaning no cracking or decoding is required for attackers to use them directly.
Why Plaintext Passwords From SBoards Create an Immediate Threat
Most breaches expose hashed passwords, which at least require extra steps for attackers to crack. SBoards stored passwords in plaintext, meaning anyone who accesses this dataset gets ready-to-use login credentials with no additional work required. Attackers can feed these email and password combinations directly into automated tools that test them against popular services like Gmail, banking apps, and shopping sites. The risk is partcularly high for anyone who reused their SBoards password on other accounts.
What Was Exposed in the SBoards Breach
- Email Address
- Plaintext Password
Why This Breach Matters Even Though SBoards No Longer Exists
The fact that SBoards shut down does not make the data go away. Once a breach dataset enters underground markets, it circulates indefinitely. Credential stuffing attacks using SBoards data can compromise accounts on active platforms today. If you registered with SBoards and used the same email and password anywhere else, you are accessable to account takeover, identity theft, and potentially financial fraud right now without any warning.
How a Database Breach Works
A database breach happens when an attacker gains unauthorized access to a website's stored data, either through a software vulnerability, a misconfigured server, or compromised admin credentials. Websites that store passwords in plaintext, as SBoards did, create a particularly serious risk because no additional cracking is needed once the data is stolen. The attacker simply downloads the database and immediately has working email and password pairs ready for use in automated attacks.
Check If Your Data Was Exposed
HEROIC's free breach scanner covers more than 400 billion compromised records including the SBoards dataset. Enter your email address to find out in seconds whether your information was part of this breach or any of thousands of other incidents in our index. If you find a match, we will show you what was exposed and guide you on what to do next. Check your exposure for free at HEROIC today.
Breach Breakdown
127,686 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds