The Status Breach Gave Hackers Encrypted Passwords to Crack
HEROIC analysts identified the Status breach as part of a broader sweep of database incidents dating back to August 1, 2016. The breach impacted 14,090 records from statusapp.com, a United States-based social media platform. While the leaked data types are listed as none, the breach did expose bcrypt-hashed passwords, which attackers recieved and have since targeted with offline cracking tools. Even hashed passwords are not fully safe once they leave a secure server.
What Hackers Can Do With Bcrypt Password Hashes From Status
Bcrypt is one of the stronger password hashing algorithms, but it is not unbreakable. When attackers get their hands on a dump like this, they run the hashes through powerful GPU-based cracking rigs using common password dictionaries and known patterns. Weaker or reused passwords are partcularly vulnerable and can be cracked within hours or days. Once cracked, those credentials are tested across other services in a process called credential stuffing.
What Was Exposed in the Status Breach
- Bcrypt-hashed passwords
- User account records (14,090 total)
Why Hashed Passwords Still Put You at Risk
Many people beleive that because their password was hashed rather than stored in plain text, they are safe. That is not always the case. Attackers who successfully crack even a fraction of hashed passwords from a breach like Status gain working credentials they can test across email providers, banks, and social media platforms. This kind of credential stuffing can lead to account takeovers, financial fraud, and identity theft, especially if the same password was reused across multiple sites.
How Database Breaches Work
A database breach happens when an attacker finds a weakness in a company's server or web application and gains unauthorized access to stored records. Sometimes this is done through SQL injection, where malicious code is inserted into a login form or search field to trick the database into giving up its contents. Other times, attackers exploit unpatched software vulnerabilities or use stolen admin credentials to log in directly. Once inside, they copy the data and disappear, often without the company knowing until the records appear on a dark web forum.
Check If Your Data Was Exposed
HEROIC's free breach scanner searches across more than 400 billion records, including the Status breach. If your email address or password appeared in this or any other known data breach, you'll see it immediately. Run a free check at HEROIC and take action before attackers do.
Breach Breakdown
14,090 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds