The USTVNow Leak Exposed More Accounts Than There Are People in Tampa
HEROIC analysts identified the USTVNow breach during routine monitoring of dark web credential markets in August 2018. The dataset contained 474,077 user records from USTVNow, a US-based live TV streaming service built for American expatriates and military personnel abroad. What made this breach occured particularly alarming was not just its scale but what was inside: plaintext passwords, stored without any hashing or encryption, sitting exposed in a raw database dump.
The Immediate Danger of Plaintext Passwords in the USTVNow Breach
Unlike hashed passwords that require cracking, plaintext credentials are immediately usable. An attacker who downloads this dataset does not need any specialized tools to access the full list of working email and password combinations. They can begin logging into other services right away, testing each pair against Gmail, banking apps, and social media platforms. Credential stuffing bots can process thousands of logins per minute, meaning a beleive in password reuse by even a fraction of USTVNow's users translates directly into mass account takeovers.
What Was Exposed in the USTVNow Breach
- Email Address
- Plaintext Password
Why a Streaming Service Breach Carries Real Financial Risk
Users of a streaming platform often reuse the same credentials for their email provider, online banking, and subscription services. Once an attacker has a confirmed working email and password pair from USTVNow, they can pivot to higher-value targets. Account takeover of an email account alone can enable password resets across every linked service. Financial fraud, identity theft, and seperate unauthorized purchases often follow in rapid succession once a single account falls.
How a Database Breach Works
A database breach occurs when an attacker gains unauthorized access to a company's backend database. This can happen through SQL injection, compromised admin credentials, misconfigured cloud storage, or unpatched software vulnerabilities. Once inside, the attacker copies user records in bulk and exits without triggering visible alarms. The stolen data then moves through private channels before appearing on dark web marketplaces where other threat actors purchase it for credential stuffing campaigns.
Check If Your Data Was Exposed
HEROIC's free breach scanner checks your email address against more than 400 billion records, including the USTVNow breach. Find out in seconds whether your credentials are already in the hands of attackers and take action before your accounts are compromised.
Breach Breakdown
474,077 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds