SMSExpert
We've been closely tracking the resurgence of older breach datasets appearing on underground forums, often bundled into "combolists" targeting specific demographics or regions. What really struck us with the reappearance of the SMSExpert data was not its size, but the timing. The original breach occurred in 2018, yet it's only now seeing significant circulation, suggesting a renewed interest in leveraging older, potentially still-valid credentials. This points to a persistent threat from credential stuffing attacks, particularly against individuals who may reuse passwords across multiple platforms.
SMSExpert's 2018 Breach Resurfaces, Fueling Credential Stuffing Concerns
A data breach impacting the now-defunct Polish mental health informational website, SMSExpert, has resurfaced after initially occurring in August 2018. The breach, affecting 15,719 users, exposed email addresses and password hashes. While the data itself is not new, its recent reappearance on underground forums is concerning. It suggests that threat actors are actively seeking out older datasets to leverage in credential stuffing attacks, hoping to find valid credentials that have been reused on other platforms. We discovered the re-emergence of this data through monitoring of several dark web forums known for trading in combolists and credential dumps. The specific forum posts highlighted the Polish origin of the data, suggesting a targeted campaign against Polish-speaking users or services popular in Poland. This breach matters to enterprises because it underscores the long-term risk associated with compromised credentials and the need for continuous monitoring and proactive password reset policies, even for seemingly "old" breaches.
- Total records exposed: 15,719
- Types of data included: Email addresses, Password hashes (format unknown)
- Source structure: Database, Combolist
- Leak location(s): Underground forums known for trading combolists.
- Date of first appearance: August 26, 2018 (original breach), recent circulation observed in October 2024.
The reappearance of the SMSExpert breach aligns with a broader trend of threat actors targeting specific demographics with credential stuffing attacks. According to a 2023 Verizon Data Breach Investigations Report, credential stuffing attacks continue to be a significant threat vector, accounting for a substantial percentage of web application breaches. While specific details about the password hashing algorithm used by SMSExpert remain unknown, the lack of readily available information suggests it may be outdated or weak, further increasing the risk of successful password cracking. The timing of this resurgence also coincides with increased chatter on Telegram channels dedicated to sharing and trading combolists, as noted by security researchers at Recorded Future. One Telegram post claimed that the dataset was "freshly cracked" despite its age, likely referring to its recent addition to a larger combolist being actively traded.
Breach Breakdown
15,719 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds