The Striker Securities Dump: 9,206 Login Credentials Exposed
On August 21, 2018, data from Striker Securities was published on a prominent hacking forum. Striker Securities is a U.S.-based financial services firm specializing in the automated execution of third-party trading systems. The breach exposed 9,206 records containing email addresses and plaintext passwords. When a financial services company stores user passwords in plaintext and that database is breached, the consequences are immediate and severe. There is no hash to crack, no decryption step, no computational barrier. Every credential in this dump was immediately ready to use against any account where the same password had ever been reused, including brokerage accounts, banking portals, and trading platforms.
Why This Is Dangerous
Financial services accounts are among the highest-value targets for credential attackers. A working username and password for a trading or brokerage platform can give an attacker direct access to funds, positions, and personal financial data. The Striker Securities breach exposed plaintext passwords specifically, meaning no cracking tools were needed. Credential stuffing campaigns targeting financial platforms frequently use exactly this type of data: real email addresses paired with real passwords that users likely reused across multiple services. The 9,206 records here represent more than a database entry. Each one is a potential direct pathway into a real person's financial accounts. The risk does not disapear with time; credential databases like this one are actively recycled and redistributed for years after the original leak.
What Was Exposed
- Email Addresses
- Plaintext Passwords
Why This Matters
A financial services firm holding user credentails in plaintext represents a fundamental security failure. Industry standards, including guidance from NIST and PCI DSS, have long required that passwords be stored using strong hashing algorithms with salting. Plaintext storage means that any successful database intrusion, regardless of the method used, results in fully usable credentials being handed to attackers with no further effort required. The data from Striker Securities has been available on hacking forums since 2018, and like most credential dumps of this era, it has almost certainly been ingested into larger combolists that continue to circulatte across dark web marketplaces and criminal channels today. The longer these credentials remain unchanged, the greater the cumulatve exposure.
How Database Breaches Work
Database breaches at financial firms typically occur through one of several vectors: SQL injection attacks against web application endpoints, compromised administrative credentials providing direct database access, or exploitation of unpatched vulnerabilities in database management software. Once an attacker has read access to a database, extracting user tables containing email addresses and passwords takes minutes. The data is then packaged and distributed through criminal channels, most commonly posted to hacking forums where it reaches a wide audience quickly. In the case of Striker Securities, the data appeared on a well-known forum, meaning it was accessible to a large number of threat actors simultaneously from the moment of posting. Financial services breaches of this type are taken seriously by regulators precisely because the downstream harm to individual victims can be direct and financial, not merely reputational.
Check If You Are Affected
HEROIC's free scanner checks your email address against a database of over 400 billion exposed records, including financial sector breaches like Striker Securities and the combolists they are routinely incorporated into. If you ever held an account with Striker Securities or used the same email and password combination on any other financial platform, you should check your exposure immediately. Run a free scan now to find out whether your data appears in this breach or any other known data exposure. If your credentials are found, change your passwords across all accounts that share them and enable two-factor authentication on every financial service you use.
Breach Breakdown
9,206 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds