Inside the Text.ru Database Breach: How Weak MD5 Hashes Put 3.5M Credentials at Risk
HEROIC analysts uncovered a database breach linked to Text.ru, a Russian online writing and plagiarism-checking tool, with the incident dated to January 2021. The breach exposed 3,491,193 records, and the inclusion of MD5-hashed passwords alongside email addresses and usernames makes this dataset accessable to credential attackers even years after the initial exposure.
Why MD5 Password Hashes and Usernames Are a Credential Stuffing Risk
MD5 is a weak hashing algorithm that can be reversed using precomputed rainbow tables or brute-force tools. When attackers obtain MD5 hashes alongside usernames and email addresses, they can quickly crack a significant portion of the passwords. Those recovered credentials are then tested across other platforms, particularly email providers, banking sites, and corporate login portals, in automated credential stuffing attacks that can occured at massive scale.
What Was Exposed in the Text.ru Breach
- Email Address
- Password Hash
- Username
- IP Address
Why IP Addresses in a Credential Breach Compound the Risk
The presence of IP addresses alongside email and password data is seperate from typical breach concerns but adds a layer of exposure. IP addresses can reveal approximate physical locations and, when combined with account credentials, help attackers build targeting profiles. For individuals who used corporate networks or VPNs when accessing Text.ru, this data point may also expose organizational infrastructure. The combination fuels targeted phishing and, in some cases, account takeover of higher-value services.
How a Database Breach Works
A database breach occurs when an unauthorized party gains access to a stored collection of records by exploiting a vulnerability such as SQL injection, a misconfigured server, or stolen administrative credentials. Once inside, the attacker extracts the structured data. In the case of Text.ru, the exposed database contained user account information including hashed passwords, which attackers can attempt to crack offline without any further access to the target system.
Check If Your Data Was Exposed
Use HEROIC's free breach scanner, powered by a database of over 400 billion records, to check whether your email address appears in the Text.ru breach or any other known credential leak. Early detection gives you the window to change reused passwords before attackers do.
Breach Breakdown
3,491,193 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds