Voudemochila
We noticed an unusual spike in credential stuffing attempts targeting our federated identity provider, originating from a cluster of IPs previously associated with brute-force attacks. What struck us was the sheer volume and the rapid succession of login failures, indicating a highly organized and automated campaign. Further investigation revealed that the attack vector leveraged a substantial list of previously compromised credentials, suggesting a connection to a recent, large-scale data leak. The targeting pattern was not random; it focused on user accounts with common email domain suffixes, a tactic often employed when exploiting publicly available breach data.
The root cause of the increased credential stuffing activity appears to be the dissemination of a dataset originating from Voudemochila, a now-defunct Brazilian tourist information platform. This breach, dated August 26, 2018, exposed approximately 9,164 unique email addresses, each paired with its corresponding plaintext password. The data was subsequently surfaced on a prominent cybercrime forum, likely serving as a valuable resource for attackers seeking to perform credential stuffing against other online services. The structure of the leaked data suggests a direct database dump, with no significant obfuscation or encryption applied to the credentials. This type of leak, where plaintext passwords are readily available, significantly lowers the barrier to entry for attackers, enabling them to test these credentials across a wide array of platforms, including our own.
While Voudemochila itself is no longer operational, the residual impact of its data compromise continues to manifest. Such leaks, often referred to as "combolists" when combined with usernames or emails, are a persistent threat in the cybersecurity landscape. Research from organizations like Troy Hunt's "Have I Been Pwned" consistently highlights the reuse of credentials across multiple services, making older, publicly available breaches a perpetual source of compromised credentials. The discovery of this specific dataset in circulation underscores the long tail of data breach impact and the ongoing need for robust identity protection strategies, including multi-factor authentication and continuous monitoring for anomalous login behavior.
Breach Breakdown
9,164 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds