If You Had an Account on Strongbow’s ISCWT, This 2022 Data Breach Should Worry You
HEROIC analysts found records from Strongbow's ISCWT -- an online platform for a German dog breeder -- posted to a prominent hacking forum following a breach discovered on July 19, 2022. The dataset exposed 1,535 unique records containing email addresses, full names, and IP addresses. While the number of records is relatively small, the combination of real names, email addresses, and IP addresses gives attackers enough to run targeted phishing campaigns and identity-based attacks against real, identifiable people.
Why This Is Dangerous
Even without passwords, this breach is a serious risk. An attacker with your full name, email address, and IP address can craft highly convincing phishing emails that appear to come from services you actually use. They can also correlate your IP address with your physical location, building a profile that makes social engineering attacks far more effective. For users of a niche community platform like Strongbow's ISCWT, the breach also signals that their involvement with the platform is now public -- which could be leveraged in targeted scams or impersonation attacks.
What Was Exposed
- Email Address
- First Name
- Last Name
- IP Address
Why This Matters
Personal information breaches like this one are the raw material for identity theft. Criminals use names and email addresses to open fraudulent accounts, apply for credit, or impersonate victims in communications with banks and government agencies. IP addresses help attackers narrow down your location and internet provider, which can be used to spoof your identity or conduct targeted intrusion attempts. Even if you changed your password after this breach, the personal details exposed here do not expire -- they can be used against you years later.
How Database Breaches Work
Most database breaches begin with an attacker discovering a vulnerability in a website's code or server configuration -- most commonly SQL injection, where malicious commands are inserted into form fields or URLs to trick the database into handing over its contents. In Strongbow's ISCWT's case, the breach appears to have been a direct extraction from the user registration database. The extracted data was then posted to a hacking forum, where it became immediatly available to anyone willing to download it. Small platforms like this one are frequent targets precisely because they often lack the security resources of larger organizations.
Data from smaller niche breaches is often combined with data from larger leaks to create detailed profiles on individuals. Even a dataset of 1,535 records can be valuable when combined with other sources -- a practice known as data enrichment -- which is why no breach should be considered too small to matter.
Check If You Are Affected
HEROIC's free scanner searches over 400 billion exposed records, including the Strongbow's ISCWT dataset, to tell you instantly if your email address was caught up in this or any other known breach. Enter your email to check now -- and if you find a match, be on alert for phishing emails and consider whether any accounts tied to that address need extra protection.
Breach Breakdown
1,535 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds