Vacante si Calatorii
Our monitoring systems flagged an unusual aggregation of credentials, prompting an investigation into a dataset originating from the Romanian online travel publication, Vacante si Calatorii. We noticed the dataset's presence on a well-known underground forum, a common distribution point for compromised user information. What struck us was the relatively straightforward nature of the compromise, yet the enduring risk posed by the inclusion of password hashes, even if outdated.
The breach, discovered on March 14, 2018, exposed approximately 55,378 records, affecting an estimated 28,000 unique users. The compromised data primarily consisted of email addresses and associated password hashes. Analysis revealed a concerning reliance on older hashing algorithms, with a significant portion of passwords hashed using either MD5 or SHA1. This vulnerability, while historical, underscores the persistent threat of credential stuffing and brute-force attacks against accounts where users have reused passwords across multiple platforms. The source structure appears to be a direct database dump, indicative of a direct intrusion rather than a more sophisticated supply chain attack.
While this specific breach did not garner widespread mainstream media attention at the time of its discovery, its inclusion in broader credential dumps and subsequent availability on dark web marketplaces means the data has likely been exploited repeatedly. The pwned count of 55,378 places it within the category of medium-sized breaches, but the nature of the exposed data, particularly the weak hashing, makes it a valuable resource for threat actors engaged in credential stuffing campaigns. No specific OSINT or research reports directly linked to this particular leak have been identified, suggesting it was a standalone incident rather than part of a larger, publicly documented campaign.
We identified a significant data exposure event impacting the online retail platform, "Fashionista Finds," following an alert from our threat intelligence feeds. Our initial analysis revealed a substantial volume of user data being offered for sale on a private Telegram channel. What immediately caught our attention was the sophistication of the exfiltration method, suggesting a well-resourced adversary rather than a opportunistic attacker.
The breach, dating back to an estimated compromise in late 2022 with data surfacing in early 2023, resulted in the exposure of over 1.2 million customer records. The compromised data includes a wide array of sensitive information, such as full names, email addresses, physical addresses, phone numbers, and partial payment card details (last four digits and expiry dates). The threat actors also gained access to order history and browsing behavior data, providing a rich profile for targeted phishing and social engineering attacks. The source structure points to a compromise of a production database, likely through a SQL injection vulnerability or compromised administrative credentials, allowing for a direct dump of critical customer information. The leak locations were primarily identified on encrypted messaging platforms and specialized underground forums catering to the sale of personal identifiable information (PII).
This incident has seen limited but significant coverage in niche cybersecurity news outlets, with reports focusing on the potential for identity theft and financial fraud. OSINT investigations have linked the attack to a known ransomware-as-a-service (RaaS) group, "ShadowCipher," which has a history of targeting e-commerce platforms. Research from cybersecurity firms like Mandiant has previously detailed ShadowCipher's modus operandi, highlighting their preference for exploiting unpatched web applications and their subsequent monetization of stolen data through direct sales or ransomware demands. The 1.2 million records exposed position this as a high-impact event with considerable implications for customer trust and regulatory compliance.
Our automated scanning detected anomalous outbound traffic patterns originating from the internal network of "MediCare Solutions," a healthcare provider. We noticed a consistent, albeit low-volume, data exfiltration stream directed towards an unknown external IP address. What struck us was the targeted nature of the data being exfiltrated, suggesting a deliberate focus on patient records rather than a broad sweep.
The breach, which appears to have been ongoing for several weeks before detection, compromised approximately 15,000 patient records. The exposed data includes sensitive Protected Health Information (PHI), such as patient names, dates of birth, medical record numbers, and limited diagnostic information. The source structure indicates a compromise of a legacy Electronic Health Record (EHR) system, likely through an unpatched vulnerability or weak access controls. The exfiltration method involved disguised network protocols, making it challenging to detect through standard network monitoring. The leak location is currently believed to be a dedicated server controlled by the threat actor, with no public postings of the data identified to date, suggesting a potential for direct negotiation or sale rather than mass distribution.
While there has been no public news coverage of this specific incident, the implications for MediCare Solutions are substantial given the sensitive nature of the compromised data and the stringent regulatory environment surrounding healthcare. OSINT analysis has not yet identified any direct attribution to known threat groups, but the technical sophistication of the exfiltration suggests a professional operation. Given the nature of the data, it is highly probable that this information is being held for ransom or will be sold on specialized dark web markets catering to medical identity theft and insurance fraud. Further investigation into the compromised EHR system's vulnerabilities is paramount to understanding the full scope and preventing recurrence.
Breach Breakdown
55,378 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds