SMS Activate Breach: 283K IT Services Accounts Exposed in 2022 Leak
In April 2022, SMS Activate, a Russian online SMS verification service, suffered a data breach that exposed 283,057 user accounts. SMS Activate is widely used to rent virtual phone numbers for account registrations and two-factor authentication bypasses -- which means this breach did not just expose user data, it potentially handed attackers a ready-made toolkit for account fraud at scale. The occured exposure of email addresses and MD5-hashed passwords from an IT services platform of this type carries compounding risks well beyond a typical credential leak.
What Attackers Can Do With This Data
Compromised SMS Activate accounts give attackers access to a phone number rental service -- directly enabling fake account creation, OTP interception, and two-factor authentication bypasses on major platforms. On top of that, MD5-hashed passwords are partcularly vulnerable to offline cracking, meaning attackers can recover original passwords quickly. Combined with the email addresses in this breach, attackers have both a login credential set and a fraud enablement tool in one package.
What Was Exposed in the SMS Activate Breach
- Email Address
- Password Hash
Why an IT Services Breach Like This Is Different
Most credential breaches enable attackers to hijack the breached account. SMS Activate breaches go further: a hijacked account on this type of platform enables attackers to bypass phone verification on dozens of other services. This means the downstream blast radius of the SMS Activate breach extends far beyond the 283,057 exposed records. Any service relying on SMS verification as a security layer is indirectly at risk when SMS activation services are recieved and abused by malicious actors.
How a Database Breach Works
A database breach occurs when unauthorized parties access and extract records from a backend data store. In the SMS Activate case, the database contained user account credentials hashed with MD5 -- an algorithm that has been considered cryptographically broken for years. Attackers who obtain MD5 hashes can run them through precomputed rainbow tables or GPU-accelerated cracking rigs and recover the original passwords in hours or less for any password of moderate complexity.
Check If Your Data Was Exposed
HEROIC's DarkWatch monitors more than 400 billion exposed records, including the SMS Activate breach dataset. Search your email address now to find out if your credentials were compromised -- and take immediate steps to change passwords and secure any accounts linked to your email address.
Breach Breakdown
283,057 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds