World Picks
We noticed a recent surge in credential stuffing attempts targeting user accounts associated with a variety of online services. Digging into the origin of these compromised credentials, our investigation led us to a data dump surfaced on a well-known hacking forum. What struck us was the specific nature of the compromised platform, a niche sports betting and prediction site that ceased operations some time ago. The persistence of these older credentials in active attack chains underscores a persistent challenge in user security hygiene and the long-term viability of legacy data in the threat landscape.
The breach, dating back to August 26, 2018, involved the platform known as World Picks. This specialized service catered to the European sports market, offering betting and prediction functionalities. The exposed dataset contained 3,069 records, comprising email addresses and SHA-1 password hashes. The nature of the exposure suggests a direct database compromise rather than a simple file leak. The SHA-1 hashing algorithm, while once considered secure, is now widely recognized as vulnerable to collision attacks, meaning these hashes could potentially be cracked to reveal plaintext passwords. The fact that these credentials are still being actively weaponized in combolists highlights the enduring risk posed by older, less secure hashing methods and the difficulty organizations face in forcing users to update credentials from defunct services.
While this specific incident did not garner widespread mainstream news coverage at the time of its initial exposure, it is emblematic of a broader trend observed in the OSINT community and cybersecurity research. The reuse of credentials across different platforms, coupled with the longevity of exposed data on dark web forums, contributes to the ongoing effectiveness of combolist attacks. Researchers have consistently documented the lifecycle of data breaches, demonstrating how seemingly old or insignificant datasets can remain valuable to threat actors for years, particularly when combined with other leaked information to form comprehensive attack profiles.
Breach Breakdown
3,069 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds