Search Your Email: The WorldTrading Breach Exposed 19K Accounts
HEROIC analysts identified the WorldTrading breach as part of a broader review of financial platform credential leaks circulating in underground forums. The breach, which occured in August 2018, exposed 19,333 user records from a now-defunct US-based international trading service. The data included email addresses and password hashes, but the hashing method used, MD5 with a salt, is considered weak by today's standards and can be cracked with widely available tools. That means many of these passwords are effectively in plaintext for anyone with basic cracking software.
Why MD5 Password Hashes from a Financial Site Are Dangerous
WorldTrading was a financial platform, which means its users were likely also registered on other financial or investment services. Attackers who crack these MD5 hashes get real passwords, which they then run against banking portals, brokerage accounts, and email providers. The combination of a financial audience and a seperate, weak password protection scheme makes this breach more serious than its modest size might suggest. Credential stuffing attacks fueled by this data could lead directly to account takeovers and financial loss.
What Was Exposed in the WorldTrading Breach
- Email Address
- Password Hash
Why Financial Platform Breaches Carry Extra Risk
When a financial service leaks user credentials, the downstream consequences tend to be worse than those from entertainment or retail breaches. Users of trading platforms often share passwords across their brokerage accounts, investment apps, and banking portals. Even a hashed password from 2018 can be cracked and used today through credential stuffing, giving attackers access to accounts where real money is at stake. Identity theft and financial fraud are both realistic outcomes when this kind of data lands in the wrong hands.
How a Database Breach Works
A database breach happens when an unauthorized party accesses the back-end storage system of a website or application. Attackers commonly exploit vulnerabilities in the site's code, gain access through stolen admin credentials, or take advantage of misconfigured servers. Once inside, they can export the entire user table, which typically contains email addresses, usernames, and stored passwords. In WorldTrading's case, the passwords were hashed with MD5, an algorithm designed to be fast, which unfortunately makes it easy to reverse with modern hardware using a technique called brute force cracking.
Check If Your Data Was Exposed
HEROIC's free breach scanner checks your email address against more than 400 billion records, including the WorldTrading leak and thousands of other breaches from financial, retail, and social platforms. If your email appeared in this breach, you should change that password immediately on any service where you used it, and enable two-factor authentication to protect your accounts going forward. Run your search now at HEROIC and find out in seconds.
Breach Breakdown
19,333 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds