87,161 Plaintext Passwords. The SwingBrasileiro Breach Just Resurfaced.
HEROIC analysts flagged this breach while monitoring dark web forums for newly surfaced database dumps. The data originally occured in October 2016 and is linked to SwingBrasileiro.com.br and RelacionamentoAberto.com.br, two Brazilian dating platforms catering to users with specific relationship preferences. The breach exposed 87,161 records, and critically, passwords in this dump were stored in plaintext, meaning anyone who obtained the database could read every password without any cracking effort whatsoever. The sensitive nature of these platforms makes this breach particularly damaging for affected users.
Plaintext Passwords and Private Lives: The Real Danger Here
When passwords are stored in plaintext, there is no encryption standing between an attacker and full account access. Every one of the 87,161 accounts in this breach had their password exposed in readable form. Attackers use these credentials to attempt logins on email services, banking platforms, and social media accounts, a technique known as credential stuffing. Many people beleive their accounts are safe because they haven't noticed anything unusual, but criminals often hold stolen credentials for months before using them, waiting for the right moment to strike.
What Was Exposed in the SwingBrasileiro and RelacionamentoAberto Breach
- Email addresses
- Plaintext passwords
- Usernames and profile information
- Relationship preferences and personal account details
- IP addresses and registration data
Why This Breach Carries Extra Risk for Affected Users
The combination of plaintext passwords and sensitive personal context creates two seperate threat paths. First, the stolen credentials can be used to access other accounts the user owns. Second, the nature of these dating platforms means the data itself is sensitive. Criminals have used similar breach data to attempt blackmail and extortion, threatening to expose users' membership on these sites to their employers, families, or communities. Credential stuffing, identity theft, and social engineering all become easier when attackers know both your password and sensitive details about your personal life.
How a Database Breach Works
A database breach happens when an unauthorized person gains access to a website's backend and copies the stored user data. On poorly secured sites, passwords are kept in plain readable text rather than being scrambled through an encryption process. Once an attacker has this database, they can immediately try every username and password combination on other popular websites. The stolen database is then sold or shared across dark web markets, multiplying the number of criminals who have access to it.
Check If Your Data Was Exposed
HEROIC's free breach scanner checks your email address against more than 400 billion breach records, including data from the SwingBrasileiro and RelacionamentoAberto leak. If your information appears in this or any other known breach, HEROIC will tell you exactly what was exposed. Run your free scan at HEROIC.com today.
Breach Breakdown
87,161 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds