Twinner
We noticed a concerning resurgence of credentials associated with the defunct Taiwanese business directory, Twinner, appearing in recent threat intelligence feeds. This particular dataset, originally surfaced in August 2018, continues to be a vector for credential stuffing attacks against other platforms. What struck us was the persistent use of these plaintext passwords, even years after the breach and the company's subsequent dissolution. The sheer volume of exposed credentials, while not astronomical by today's standards, represents a significant risk when aggregated with other compromised datasets, amplifying the effectiveness of automated attack techniques.
The Twinner breach, discovered on August 21, 2018, exposed 15,064 user records. The compromised data primarily consisted of email addresses and, critically, plaintext passwords. This breach originated from a database compromise, with the resulting data being distributed as a combolist on a prominent hacking forum. The implications are significant; the availability of plaintext passwords allows attackers to directly attempt logins on other services where users may have reused these credentials. This practice, unfortunately common, transforms a seemingly isolated breach into a widespread credential stuffing campaign, impacting not only former Twinner users but also the security posture of any service they interact with.
While Twinner itself is no longer operational, its data continues to circulate within the dark web ecosystem. This incident predates widespread adoption of multi-factor authentication for many services, making the plaintext password exposure particularly potent. Research into credential stuffing consistently highlights the effectiveness of using older, widely distributed combolists like this one to gain unauthorized access to accounts. The longevity of such datasets underscores the importance of proactive credential monitoring and the continuous need for users to practice robust password hygiene, including the use of unique passwords across different online services.
Breach Breakdown
15,064 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds