Unique Readers Service Data Breach — October 2018: 17,385 US Records
Unique Readers Service: When an Unknown Hash Format Clouds the Risk Picture
In October 2018, Unique Readers Service -- a US-based subscription platform offering bundeld magazine packages with features like address updates and title swaps -- was breached, exposing 17,385 user records. The leaked data included email addresses and password hashes in an unconfirmed format. This ambiguity is itself significant. When a breach dataset contains password hashes in an algorythm that cannot be immediately identified, security analysts face a harder task assessing how quickly those hashes might be cracked and used for credential stuffing. The obscurd format may represent an outdated proprietary hashing scheme, a poorly implemented standard algorithm, or a salted variant that reduces but does not eliminate crackability risk.
Unique Readers Service (October 2018): Data Breach Summary
- Records Exposed: 17,385
- Data Types: Email addresses, password hashes
- Breach Type: Database breach -- credentials exfiltrated from a compromised server database
- Password Type: Unknown hash format -- crackability cannot be confirmed without additional analysis
- Country: United States
- Date Leaked: October 16, 2018
The Risk Spectrum of Password Hash Types
Not all password hashes carry equal risk. At the highest-risk end, plaintext and Base64-encoded passwords require no cracking. MD5 hashes, while technically one-way, are trivially reversible for common passwords using precomputed rainbow tables or modern GPU cracking rigs. MD5 with per-user salts slows this process but does not prevent it. PHPass (used by older WordPress and Drupal installations) offers more resistance. Bcrypt and Argon2, at appropriately high cost factors, represent the current standard for resistant password storage. The "unknown format" classification for Unique Readers Service means the dataset falls somewhere in this spectrum -- but without format confirmation, the exact risk level for the 17,385 affected users cannot be precisely determined.
Subscription Platforms as Identity Data Sources
Magazine subscription services collect a specific and valuable subset of personal information: mailing addresses, payment histories, reading preferences, and demographic data. Even when a breach exposes only email addresses and password hashes, the platform's underlying data model suggests additional PII may have been stored and potentially accessible to the same attacker. Subscription platforms that offered address change features, as Unique Readers Service did, maintained physical mailing addresses for their subscribers -- information that has value beyond credential stuffing for identity fraud and physical mail-based social engineering. The October 2018 breach surfaced on underground sources, indicating it reached criminal markets where multiple forms of data extraction would be considered.
The Long Tail of 2018 Breach Data
The October 2018 breach of Unique Readers Service places it in a cohort of thousands of platform compromises from that year, many of which remain in circulation in aggregated combolist databases today. Breach data from 2018 continues to appear in credential stuffing campaigns because many users have never rotated passwords from accounts on defunct or obscure platforms. A user who registered on Unique Readers Service in 2016, used the same password on their primary email account, and has never changed either password remains at risk from this 2018 dataset today. HEROIC's tracking of historical breaches like this one exists precisely to alert those users before an attacker finds the connection first.
Check If Your Data Was Exposed
HEROIC's free breach scanner searches across more than 400 billion exposed records, including historical database breaches like Unique Readers Service. If your email address appears in this dataset, HEROIC will alert you so you can review and rotate any potentially compromised credentials. Run a free scan at HEROIC.com.
Breach Breakdown
17,385 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds