Researchers Link Truong Buu Diep Foundation to 3,504 Stolen Records
In August 2018, threat intelligence researchers identified a dataset on a prominent hacking forum attributed to the official website of Truong Buu Diep Foundation, a Vietnamese Catholic non-profit organization dedicated to the memory of a prominent martyr and priest. The database dump exposed 3,504 records containing email addresses and salted MD5 password hashes. Non-profit organizations are frequently targeted precisely because their security budgets and dedicated IT staff tend to be limited compared to commercial enterprizes, making them softer targets for attackers seeking credential data. The data has since been incorporated into broader combolists circulating through underground channels.
Why This Is Dangerous
Salted MD5 password hashes are meaningfully more resistant to cracking than unsalted MD5, but they are still far from secure by modern standards. MD5 is a deprecated algorithm, and the salting only prevents the use of precomputed rainbow tables -- it does not prevent targeted brute-force attacks using GPU-accelerated cracking tools that can test billions of hash combinations per second. For any user whose original password was shorter than 12 characters or followed predictable patterns, cracking is feasible within hours to days depending on password complexity. Once cracked, the resulting email-password pairs become ready for credential stuffing across any platform where the victim reused that password. Even if individual passwords resist cracking, the exposed email addresses alone are valuable for targeted phishing campains against the foundation's donors and community members.
What Was Exposed
- Email Address -- account identifiers for registered users of the foundation's website, usable for phishing and credential stuffing
- Password Hash (Salted MD5) -- password hashes using the deprecated MD5 algorithm with individual salts, resistant to rainbow tables but vulnerable to targeted brute-force cracking
Why This Matters
Religious and non-profit organizations occupy a unique position in the threat landscape. Their communities tend to place high trust in institutional communications, which makes the exposed email addresses particularly valuable for social engineering attacks. An attacker who successfully cracks even a subset of these passwords gains access to accounts on other platforms where those users reused their credentials -- a common behavior across all demographics. Beyond individual users, the exposure reflects a systemic vulnerability in how resource-constrained organizations approach database security and password storage standards. Organizations still using MD5 for password hashing in 2018 were already years behind current best practices.
How a Database Breach Works
A database breach targeting a website like the Truong Buu Diep Foundation's typically exploits a vulnerability in the web application layer -- most commonly SQL injection, where an attacker manipulates database queries through unsanitized input fields, or through compromised administrative credentials. Once the attacker has database access, they export the user table containing all registered account data. The exported data is then cleaned, formatted, and published on hacking forums where it can be downloaded, sold, or traded. From there, it gets incorporated into aggregated combolists used for automated credential stuffing operations at scale. The cycle repeats with each new breach feeding the next wave of attacks.
Check If You Are Affected
HEROIC's free breach scanner searches across more than 400 billion compromised records -- one of the largest breach intelligence databases in the world. If you have ever registered on the Truong Buu Diep Foundation website or used the same email and password on another service, enter your address now to check whether your data was exposed. HEROIC will show you exactly what was leaked so you can take immediate action to protect your accounts.
Breach Breakdown
3,504 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds