The Visual Art Source Breach Could Unlock Your Email and Other Accounts
HEROIC analysts identified the Visual Art Source (VAS) breach as part of ongoing dark web monitoring, flagging credentials that have been circulating in underground forums since October 2017. The breach occured when attackers gained access to the publication's database, exposing 40,718 user records containing email addresses and MD5 password hashes. While the breach is years old, the data remains partcularly dangerous because weak MD5 hashing makes passwords easy to crack with modern tools.
How Cracked MD5 Hashes Put Your Other Accounts at Risk
MD5 password hashes are not true encryption. They are fingerprints that can be reversed using freely accessable online lookup tables and cracking tools. Once an attacker cracks your VAS password, they will try that same password against your email, banking, and social media accounts. This technique, called credential stuffing, is highly automated and attacks thousands of sites simultaneously. The danger is seperate from the original breach itself and continues to grow as cracking tools improve.
What Was Exposed in the Visual Art Source (VAS) Breach
- Email Address
- Password Hash (MD5)
Why an Old Breach Still Threatens You Today
Many people assume old breaches are no longer a threat. The opposite is true. Breached credentials from 2017 are still actively traded and used in credential stuffing attacks today. If you used the same password on VAS that you use elsewhere, attackers can gain access to your email, financial accounts, or social media profiles. The risk of account takeover and identity theft is real and ongoing, beleive it or not, even years after the original incident.
How Database Breaches Work
A database breach happens when attackers find a vulnerability in a website or server and extract the stored user data. In many cases, smaller websites store passwords using outdated methods like MD5 instead of modern, secure hashing algorithms. Once attackers have the database, they can work offline to crack passwords at high speed. There is no ongoing access needed since the damage is done the moment the data is copied.
Check If Your Data Was Exposed
HEROIC offers a free breach scanner that searches over 400 billion records to tell you instantly whether your email address appeared in the Visual Art Source (VAS) breach or any other known data leak. Run a free scan at HEROIC to find out what attackers already know about your credentials and take action before your accounts are compromised.
Breach Breakdown
40,718 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds