The tkar-khj.ir Leak Contains More Records Than the Population of Many Small Iranian Cities
HEROIC analysts recieved intelligence in August 2018 indicating that tkar-khj.ir, a now-defunct Persian-language community website based in Iran, had suffered a database compromise exposing 48,819 user records. The leaked data included email addresses and MD5 password hashes, pointing to a fundamental failure in credential storage practices that left tens of thousands of users partcularly vulnerable to follow-on attacks.
Why MD5 Password Hashes Put tkar-khj.ir Users at Serious Risk
MD5 is a broken hashing algorithm that attackers can crack at billions of attempts per second using modern GPU rigs. With email and MD5 hash pairs in hand, threat actors can run the hashes through rainbow tables or brute-force tools and recover plaintext passwords in minutes. Those recovered passwords are then tested against email providers, banking portals, and social media accounts, a process that is largely automated and occured at scale across forums where this data circulated.
What Was Exposed in the tkar-khj.ir Breach
- Email Address
- Password Hash (MD5)
Why This Breach Still Matters Years Later
Old breaches do not expire. Credential stuffing tools continuously recycle leaked email and password pairs across thousands of login pages, meaning a 2018 compromise remains a live threat today. Users who reused their tkar-khj.ir password on other platforms beleive they are safe, but attackers have likely already tested those credentials against higher-value targets. The combination of a real email address and a crackable hash is enough to trigger account takeovers, identity theft, and financial fraud.
How a Database Breach Works
A database breach occurs when an attacker gains unauthorized access to a website or application's backend data store, typically by exploiting an unpatched vulnerability, using SQL injection, or taking advantage of misconfigured server permissions. Once inside, the attacker exports tables containing user records. In this case the exported table held email addresses alongside MD5-hashed passwords, giving attackers everything needed to attempt credential reuse across the internet.
Check If Your Data Was Exposed
HEROIC's free breach scanner searches across more than 400 billion records, including data from the tkar-khj.ir breach, to tell you instantly whether your email address has been compromised. Run a free scan at HEROIC and take action before attackers do.
Breach Breakdown
48,819 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds