Breach Intelligence Report 15 Sep 2025

SMSExpert

HEROIC
HEROIC Threat Intelligence Team
Email Address Password Hash
Your email may be in this breach. Check in 5 seconds — free, no signup required.
Scan Email →
Records Exposed 15,719
Source Type Database,Combolist
Origin Telegram
Password Type Other

We've been closely tracking the resurgence of older breach datasets appearing on underground forums, often bundled into "combolists" targeting specific demographics or regions. What really struck us with the reappearance of the SMSExpert data was not its size, but the timing. The original breach occurred in 2018, yet it's only now seeing significant circulation, suggesting a renewed interest in leveraging older, potentially still-valid credentials. This points to a persistent threat from credential stuffing attacks, particularly against individuals who may reuse passwords across multiple platforms.

SMSExpert's 2018 Breach Resurfaces, Fueling Credential Stuffing Concerns

A data breach impacting the now-defunct Polish mental health informational website, SMSExpert, has resurfaced after initially occurring in August 2018. The breach, affecting 15,719 users, exposed email addresses and password hashes. While the data itself is not new, its recent reappearance on underground forums is concerning. It suggests that threat actors are actively seeking out older datasets to leverage in credential stuffing attacks, hoping to find valid credentials that have been reused on other platforms. We discovered the re-emergence of this data through monitoring of several dark web forums known for trading in combolists and credential dumps. The specific forum posts highlighted the Polish origin of the data, suggesting a targeted campaign against Polish-speaking users or services popular in Poland. This breach matters to enterprises because it underscores the long-term risk associated with compromised credentials and the need for continuous monitoring and proactive password reset policies, even for seemingly "old" breaches.

  • Total records exposed: 15,719
  • Types of data included: Email addresses, Password hashes (format unknown)
  • Source structure: Database, Combolist
  • Leak location(s): Underground forums known for trading combolists.
  • Date of first appearance: August 26, 2018 (original breach), recent circulation observed in October 2024.

The reappearance of the SMSExpert breach aligns with a broader trend of threat actors targeting specific demographics with credential stuffing attacks. According to a 2023 Verizon Data Breach Investigations Report, credential stuffing attacks continue to be a significant threat vector, accounting for a substantial percentage of web application breaches. While specific details about the password hashing algorithm used by SMSExpert remain unknown, the lack of readily available information suggests it may be outdated or weak, further increasing the risk of successful password cracking. The timing of this resurgence also coincides with increased chatter on Telegram channels dedicated to sharing and trading combolists, as noted by security researchers at Recorded Future. One Telegram post claimed that the dataset was "freshly cracked" despite its age, likely referring to its recent addition to a larger combolist being actively traded.

Breach Breakdown

Domain N/A
Leaked Data Email Address,Password Hash
Password Types Other
Date Leaked 15 Sep 2025
Check in 5 seconds

15,719 passwords exposed. Is yours one of them?

Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.

All information submitted is Private and Secure. We do not sell or share email addresses. By searching, you agree to HEROIC's Privacy Policy and Terms of Service.

Free forever · No account required · Results in seconds

Private & Secure No Account Needed 3,227 scanned today
Breach Rank #10,747 by affected users
Impact Score
1
sensitivity + scale + recency
Est. Financial Impact $113.7K fraud, phishing & misuse risk
Scan your email Free →
Scan to sign up

Scan to sign up instantly

24/7 Dark Web Monitoring
Instant Breach Alerts
Secure Data Protection
Your Data is at Risk

Your Personal Information is Exposed

We found your data exposed in multiple breaches. This includes:

  • Email addresses
  • Passwords
  • Phone numbers
  • Financial information
Secure My Information Now

Your information is protected by enterprise-grade security

Your Breach Details

Date:
Severity:
Records Exposed:

Your Exposed Information

Your Risk Level

How This Affects You

Full Breach Details

Premium Insights

Unlock Critical Security Information

Create a free account to access:

  • Full Breach Impact Analysis
  • Identity Theft Risk Score
  • Exposed Credentials Details
  • Personalized Security Recommendations
Create Free Account

Identity Theft Risk Score

Risk Score: 8.7/10 - Critical

Data Exposure Analysis

Passwords Critical
Financial High
Personal Medium
Social High
Security Critical

Breach Timeline Analysis

March 2024 Multiple credentials exposed in recent data breach
January 2024 Password found in dark web marketplace
December 2023 Personal information leaked in major security incident

Security Recommendations

High Priority
Password Security

Critical: Change compromised passwords immediately and enable 2FA on all accounts

Important
Financial Protection

Monitor credit reports and set up fraud alerts with major credit bureaus

Recommended
Identity Protection

Enable advanced identity monitoring and dark web surveillance