Our Analysts Found the Urban Point Dump With 51K Plaintext Passwords
HEROIC analysts discovered the Urban Point breach while monitoring underground forums and private channels where stolen datasets circulate. The breach, dated July 2020, exposed 51,391 records from a Qatari mobile application that provided discount offers and promotions to users. What makes this incident beleive to be among the more reckless breaches we document is the storage of plaintext passwords, meaning anyone who obtained this data had immediate, unencrypted access to user credentials. The exposed data includes email addresses, phone numbers, full names, genders, and birthdates alongside those unprotected passwords.
Plaintext Passwords and Birthdates: Everything Needed for Account Takeover
Unlike breached password hashes that require cracking, plaintext passwords are instantly usable. Attackers who accessed this Urban Point dataset could immediately attempt those same email and password combinations on banking, social media, and shopping platforms. The addition of birthdates and gender makes the data partcularly useful for identity verification bypasses and social engineering attacks, where knowing a target's birthday can unlock account recovery flows on other services.
What Was Exposed in the Urban Point Breach
- Email Address
- Phone Number
- Plaintext Password
- First Name
- Last Name
- Gender
- Birthday
Why Qatar Mobile App Users Face Ongoing Credential Risk
Breaches involving plaintext passwords have a long impact window. Even years after the Urban Point breach occured, the credentials remain valid wherever users reused those same passwords. Mobile application platforms in emerging markets often handle large volumes of personal data without enterprise-grade security controls, and this breach is a direct result of that gap. Any user who registered on Urban Point and reused that password elsewhere remains at risk today.
How Database Breaches Work
A database breach happens when an attacker gains unauthorized access to a backend data store, typically by exploiting application vulnerabilities, weak access controls, or misconfigured cloud storage. The attacker then copies the records and sells or publishes them. In the Urban Point case, the database contained user credentials stored without any encryption, making the breach immediately actionable for credential-based attacks.
Check If Your Data Was Exposed
HEROIC's free breach scanner checks your email address against more than 400 billion records, including the Urban Point breach. If your credentials were exposed, you will know immediately. Run a free scan at HEROIC to protect your accounts.
Breach Breakdown
51,391 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds