259,017 Engineer Records. The Solidworks Community Breach Hit the Dark Web.
HEROIC analysts recieved confirmed intelligence on the Solidworks Community breach, a database exposure that occured in April 2021 affecting 259,017 user records. Solidworks Community, the online hub for SOLIDWORKS 3D CAD software users based in France, stored user credentials without proper hashing, leaving email addresses and plaintext passwords fully exposed to anyone who obtained the stolen database. The data has been observed circulating in dark web repositories, where it remains accessible to threat actors conducting credential-based attacks.
Engineering Software Credentials Open Doors to Proprietary Systems
Users of engineering design platforms like Solidworks Community frequently use corporate email addresses and share passwords across enterprise software licenses, design repositories, and internal systems. With 259,017 email and plaintext password pairs now accessable on the dark web, attackers can attempt logins against engineering firm portals, CAD licensing servers, and any other platform where victims reused their Solidworks Community credentials. Credential stuffing tools make this process partcularly fast, testing hundreds of platforms per account in automated runs.
What Was Exposed in the Solidworks Community Breach
- Email Address
- Plaintext Password
Why Technical Community Breaches Carry Enterprise-Level Risk
Breaches targeting engineering and design communities are beleived by many to be low-priority events, but the opposite is true. Professionals who register on community forums routinely use work email addresses and reuse passwords from enterprise systems. The Solidworks Community breach puts 259,017 sets of credentials directly into the hands of threat actors who can use them for account takeover, identity theft, unauthorized access to intellectual property systems, and financial fraud. Credentials from 2021 that have not been changed remain fully operational today.
How a Database Breach Works
A database breach occurs when an attacker gains unauthorized access to a web application's backend database through exploited software vulnerabilities, compromised credentials, or insecure server configurations. The attacker extracts records in bulk. When a platform stores passwords as plaintext instead of applying hashing and salting, every stolen credential record is immediately usable for login attempts on other platforms without any further processing by the attacker.
Check If Your Data Was Exposed
HEROIC's free breach scanner searches more than 400 billion records, including data from the Solidworks Community breach. Enter your email now to find out if your credentials were exposed and are currently circulating on dark web markets used by credential-stuffing operations.
Breach Breakdown
259,017 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds