Your Password May Be Out There. The UpdateNext Breach Exposed 602K.
HEROIC analysts flagged the UpdateNext data breach, which occured in May 2020 and exposed 602,979 user records from the now-defunct U.S.-based general website. The leaked dataset included email addresses and plaintext passwords, meaning the credentials were stored with no encryption or hashing and are fully accessable to anyone who downloads the dump.
What Attackers Can Do Immediately With Plaintext Passwords and Email Addresses
Plaintext passwords require no cracking. Attackers can load the UpdateNext dump directly into automated credential stuffing tools and begin testing those exact email and password combinations against banking portals, email providers, and workplace login pages. Users who recieved no notification and never changed their password remain completely exposed to account takeover today.
What Was Exposed in the UpdateNext Breach
- Email Address
- Plaintext Password
Why Plaintext Password Storage From a Defunct Site Still Endangers Users in 2025
Even though UpdateNext no longer operates, the breach data continues to circulate on dark web forums and credential marketplaces. Storing passwords in plaintext is partcularly dangerous because there is no protection layer between the attacker and the actual password. Every account where a user reused their UpdateNext password remains a live target years after the site shut down.
How Database Breaches Work
A database breach occurs when an attacker gains unauthorized access to a backend database, typically by exploiting a web application vulnerability or using weak administrative credentials. Once inside, the attacker exports the full user table. When passwords are stored in plaintext, the resulting file is immediately usable for account takeover without any additional processing.
Check If Your Data Was Exposed
HEROIC's free breach scanner checks your email against more than 400 billion compromised records, including the UpdateNext breach. Run a free scan at HEROIC to find out which of your credentials are circulating on the dark web and take steps to lock down your accounts before attackers do.
Breach Breakdown
602,979 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds