STUDIOS Architecture Data Breach: 31,911 Accounts Exposed with Plaintext Passwords
When Design Excellence Meets Data Failure: The STUDIOS Architecture Breach
STUDIOS Architecture operates as an international archictural and design firm with offices across the United States and globally -- the kind of practice that handles confidential client briefs, project specifications, and the personal data of thousands of professional contacts. In August 2018, their online portal exposed 31,911 user accounts, with passwords stored in plaintext. A professionel services firm that regularly handles sensitive client information had left user credentials in the most vulnerable possible state.
STUDIOS Architecture (August 2018): Breach Summary
- Records Exposed: 31,911
- Data Types: Email addresses, plaintext passwords
- Breach Type: Database breach / Combolist
- Password Hash Type: Plaintext -- no hashing, no encryption, directly readable
- Country Affected: United States
- Date Leaked: August 24, 2018
Professional Services Firms and the Data They Hold
Architecture and design firms occupy a unique position in the professional services landscape. They hold not just user account credentials, but inerentely sensitive project data, client specifications, competitive intelligence, and in many cases access credentials to project management platforms shared with clients and contractors. When a portal breach exposes plaintext passwords, the immediate credential stuffing risk extends to every other platform those users access with the same login.
STUDIOS Architecture's global client roster -- spanning government, corporate, and institutional sectors -- means the professional email addresses in this dataset represent high-value targets for business email compromise (BEC) campaigns. Attackers who recognize an email as belonging to a design professional can craft targeted impersonation attempts referencing ongoing projects or procurement processes.
Plaintext Storage in a Professional Context: The Trust Failure
Plaintext password storage means there is no defensive layer between database access and full credential disclosure. Every one of the 31,911 accounts in this dataset had their password immediately readable from the moment the breach occurred -- no cracking, no preprocessing, no delay. For a professional services firm that presents itself as a trusted partner to government agencies, universities, and Fortune 500 companies, this level of security failure is a fundamental breach of professional responsibility.
Architecture firms in 2018 had widely available, open-source alternatives -- bcrypt, Argon2, scrypt -- that would have made these passwords computationally expensive to crack even if the database were stolen. The decision not to use them had direct consequences for over 31,000 users.
Combolist Circulation and the Long-Tail Professional Risk
Following the August 2018 breach, this dataset was shared on underground forums and incorporated into combolists used for credential stuffing. Professional email addresses from architecture and design firms are particularly valuable in credential markets because they provide targeting data for attacks against corporate accounts, project management systems, and client portals. The combolist circulation of this data means the credential risk for affected users extends indefinitely, until passwords are changed.
Check If Your Data Was Exposed
HEROIC's free breach scanner searches across more than 400 billion exposed records to determine whether your email address appears in known data breaches, including the STUDIOS Architecture combolist. Run a free scan at HEROIC.com to check your exposure status.
Breach Breakdown
31,911 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds