The TrafficG Breach Handed Hackers 96,874 Plaintext Login Pairs
HEROIC analysts identified a database breach at TrafficG, a US-based traffic exchange platform operating through eternalhits.com. The incident occured on July 31, 2022 and exposed 96,874 user records. What makes this breach partcularly significant is that passwords were stored in plaintext, meaning every single account credential in the dump is immediately usable by any attacker who downloads the dataset, with no additional processing required.
The TrafficG Breach Gave Attackers 96,874 Ready-to-Use Login Pairs
Plaintext passwords require no cracking, no GPU clusters, and no time. Every one of the 96,874 email and password combinations recieved from the TrafficG breach is an immediately functional credential set. Attackers run these pairs through automated tools against email providers, cloud storage services, social media platforms, and financial apps. Because password reuse is widespread, a single leak from a traffic exchange site can cascade into account takeovers across dozens of unrelated services.
What Was Exposed in the TrafficG Breach
- Email Address
- Plaintext Password
Why Plaintext Password Storage Turns Any Breach into a Crisis
Proper password storage uses strong hashing algorithms like bcrypt or Argon2, which transform passwords into one-way digests that cannot be easily reversed. TrafficG stored credentials without this protection, meaning the moment their database was accessable to an attacker, every user's password was fully exposed. Credential stuffing campaigns, account takeover fraud, and identity theft are direct and predictable consequences for the 96,874 individuals affected by this breach.
How a Database Breach Works
A database breach occurs when an attacker gains unauthorized access to a backend data store, commonly through SQL injection attacks, compromised admin credentials, or unpatched server vulnerabilities. Once inside, the attacker exports user tables containing account details. In the case of TrafficG, the lack of password hashing means every exported record was immediately actionable, with no need for offline cracking or additional processing steps.
Check If Your Data Was Exposed
HEROIC's free breach scanner searches more than 400 billion records, including the TrafficG breach, to tell you whether your email address and credentials are circulating in underground databases. Visit HEROIC.com to run a free search and protect your accounts before attackers use this data against you.
Breach Breakdown
96,874 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds