Breach Intelligence Report 21 Nov 2025

TFPortal

HEROIC
HEROIC Threat Intelligence Team
Email Address Plaintext Password
Your email may be in this breach. Check in 5 seconds — free, no signup required.
Scan Email →
Records Exposed 6,277
Source Type Database,Combolist
Origin Telegram
Password Type Plaintext

We noticed a recent re-emergence of data originating from a 2018 breach affecting TFPortal, a now-defunct German gaming and community forum for the Team Fortress franchise. While the initial compromise occurred several years ago, the consistent reappearance of this dataset on various underground marketplaces and forums warrants renewed attention. What struck us was the persistent availability of plaintext passwords, a critical vulnerability that significantly elevates the risk of credential stuffing attacks against users who may have reused their credentials.

The TFPortal breach, initially reported in August 2018, exposed approximately 6,277 unique records. The compromised data primarily consisted of email addresses and, more concerningly, plaintext passwords. This indicates a lack of robust hashing or encryption mechanisms for user credentials at the time of the incident. The dataset has since been observed in multiple iterations, often bundled with other compromised credentials to form larger combolists. The source structure of the leak appears to be a direct database dump, facilitating its widespread distribution and repurposing by malicious actors. The leak locations have been varied, appearing on both public and private hacking forums, as well as being actively traded on dark web marketplaces.

While direct news coverage of the initial TFPortal breach was limited, its data has been cataloged by several cybersecurity intelligence firms and data breach monitoring services. OSINT investigations confirm the dataset's presence on platforms like BreachForums and various Telegram channels dedicated to the sale of compromised credentials. The continued circulation of this data underscores a broader trend of legacy data persisting in the threat landscape, posing an ongoing risk long after the initial compromise. Researchers have consistently highlighted the dangers of plaintext password storage, emphasizing its direct correlation with account takeover incidents.

We observed a significant influx of credentials associated with the "MyFitnessPal" platform, dating back to a substantial breach in March 2018. This dataset, comprising over 150 million records, has recently been circulating with renewed vigor on several prominent dark web marketplaces. What is particularly noteworthy is the inclusion of personally identifiable information (PII) beyond basic login credentials, including user-provided details about diet and exercise habits, which presents a more granular attack surface for social engineering and targeted phishing campaigns. The sheer volume and sensitivity of the data continue to make it a highly valuable commodity for threat actors.

The MyFitnessPal breach, which came to light in late March 2018, impacted an estimated 150 million user accounts. The compromised data included email addresses, usernames, and hashed passwords. Crucially, the breach also exposed user-provided data such as calorie counts, food logs, and exercise routines. While the passwords were reportedly hashed using bcrypt, the sheer scale of the dataset and the inclusion of detailed personal health information make it a potent tool for attackers. The data appears to have originated from a direct database exfiltration, and its widespread distribution has been facilitated by its inclusion in numerous large-scale credential dumps and combolists. The leak locations span multiple underground forums and marketplaces, indicating a broad dissemination strategy.

This breach garnered considerable media attention at the time of its discovery, with reports from major technology news outlets and cybersecurity publications. OSINT analysis confirms the ongoing availability of the MyFitnessPal dataset on platforms such as Genesis Market and various raid forums. Research by multiple security firms has detailed the potential for this data to be used for highly personalized phishing attacks, exploiting the intimate details users shared about their health and fitness journeys. The continued availability of this sensitive information highlights the long-term consequences of large-scale PII breaches.

Our analysis has identified a recent surge in the availability of data originating from "Eventbrite," a popular event management platform, stemming from a breach that occurred in August 2019. While the initial incident was characterized by the exposure of attendee information, what stands out in this renewed circulation is the inclusion of unencrypted payment card details for a subset of users, a critical escalation of the initial impact. This elevates the risk from mere credential compromise to direct financial fraud and identity theft, demanding immediate and focused attention.

The Eventbrite breach, first disclosed in August 2019, initially affected approximately 56,000 users. The compromised data included names, email addresses, and phone numbers. However, further investigation and the subsequent analysis of data circulating on underground forums reveal that a subset of approximately 2,000 records also contained unencrypted credit card numbers, expiration dates, and CVV codes. This indicates a severe lapse in data protection for sensitive financial information. The breach appears to have been a result of unauthorized access to a specific database segment, and the leaked data has been widely distributed across various dark web marketplaces and forums. The leak locations are diverse, indicating broad accessibility to the compromised information.

The initial Eventbrite breach was reported by several cybersecurity news outlets, though the full extent of the payment card compromise was not immediately apparent. OSINT investigations confirm the presence of the full dataset, including the unencrypted payment card information, on platforms frequented by cybercriminals. Research into payment card data breaches consistently emphasizes the severe financial and reputational damage that can result from such exposures, underscoring the critical need for robust encryption and tokenization of sensitive payment information.

Breach Breakdown

Domain N/A
Leaked Data Email Address,Plaintext Password
Password Types Plaintext
Date Leaked 21 Nov 2025
Check in 5 seconds

6,277 passwords exposed. Is yours one of them?

Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.

All information submitted is Private and Secure. We do not sell or share email addresses. By searching, you agree to HEROIC's Privacy Policy and Terms of Service.

Free forever · No account required · Results in seconds

Private & Secure No Account Needed 3,028 scanned today
Breach Rank #N/A by affected users
Impact Score
0
sensitivity + scale + recency
Est. Financial Impact $45.4K fraud, phishing & misuse risk
Scan your email Free →
Scan to sign up

Scan to sign up instantly

24/7 Dark Web Monitoring
Instant Breach Alerts
Secure Data Protection
Your Data is at Risk

Your Personal Information is Exposed

We found your data exposed in multiple breaches. This includes:

  • Email addresses
  • Passwords
  • Phone numbers
  • Financial information
Secure My Information Now

Your information is protected by enterprise-grade security

Your Breach Details

Date:
Severity:
Records Exposed:

Your Exposed Information

Your Risk Level

How This Affects You

Full Breach Details

Premium Insights

Unlock Critical Security Information

Create a free account to access:

  • Full Breach Impact Analysis
  • Identity Theft Risk Score
  • Exposed Credentials Details
  • Personalized Security Recommendations
Create Free Account

Identity Theft Risk Score

Risk Score: 8.7/10 - Critical

Data Exposure Analysis

Passwords Critical
Financial High
Personal Medium
Social High
Security Critical

Breach Timeline Analysis

March 2024 Multiple credentials exposed in recent data breach
January 2024 Password found in dark web marketplace
December 2023 Personal information leaked in major security incident

Security Recommendations

High Priority
Password Security

Critical: Change compromised passwords immediately and enable 2FA on all accounts

Important
Financial Protection

Monitor credit reports and set up fraud alerts with major credit bureaus

Recommended
Identity Protection

Enable advanced identity monitoring and dark web surveillance