If You Reuse Passwords, the Sharewatch Leak Should Worry You
In August 2018, HEROIC found 5,423 email addresses and SHA-1 password hashes from Small Company Sharewatch (SCSW) exposed on a prominent hacking forum. The data came from a UK investment newsletter focused on small-cap and growth stocks listed on the London Stock Exchange.
Why the Small Company Sharewatch (SCSW) Breach Is Dangerous
SHA-1 is a deprecated hashing algorithm susceptible to brute-force attacks, especially when users choose common or short passwords. SCSW's subscriber base consists of active investors, making cracked credentials particularly valuable for account takeover of brokerage accounts, financial services, and investment platforms where users may have reused their passwords.
What Was Exposed in the Small Company Sharewatch (SCSW) Leak
- Email addresses
- SHA-1 password hashes
Why This Small Company Sharewatch (SCSW) Data Puts You at Risk
Investors who reused their SCSW credentials elsewhere face credential stuffing risk against trading platforms, banking apps, and financial email accounts. Cracked SHA-1 hashes also enable targeted phishing campaigns tailored to financially active users, who are more likely to respond to investment fraud or account security alerts crafted using their personal details.
How a Database Breach Works
Database breaches typically involve an attacker exploiting a vulnerability to access and extract an organization's user records. The stolen data, including email addresses and hashed passwords, is then published on underground forums. SHA-1, though stronger than MD5, has well-known weaknesses and password recovery is feasible for attackers with adequate computing resources and access to password cracking tools.
Check If Your Data Was Exposed
HEROIC operates one of the world's largest breach databases, covering more than 400 billion leaked records. Use HEROIC's free breach scanner to check if your email address or credentials appeared in the Small Company Sharewatch (SCSW) leak or thousands of other breaches in our database.
Breach Breakdown
5,423 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds