Xin Mu Cha (芯沐茶)
We noticed a recent resurgence of interest around a dataset originating from August 2018, now circulating on a prominent hacking forum. This particular breach, impacting Xin Mu Cha (芯沐茶), a Taiwanese online retailer specializing in premium teas, exposed the credentials of 9,811 users. What struck us was the continued availability and potential repurposing of this relatively old, yet highly sensitive, data. The simplicity of the exposed information—email addresses paired with plaintext passwords—makes it a prime candidate for credential stuffing attacks, especially against users who may have reused these credentials across multiple platforms.
The breach, discovered on August 26, 2018, originated from a database compromise affecting Xin Mu Cha's user base. A total of 9,811 records were exfiltrated, comprising two critical data types: email addresses and plaintext passwords. The source structure indicates a direct dump from a user authentication database. The significance of this leak lies in the unencrypted nature of the passwords, rendering them immediately actionable for attackers. This type of data is a cornerstone for building effective combolists, enabling threat actors to automate login attempts across a wide array of online services, from e-commerce platforms to social media and potentially even corporate access points if credential reuse is prevalent.
While this specific breach did not garner widespread mainstream media attention at the time of its discovery, its reappearance on hacking forums suggests ongoing utility for malicious actors. The exposure of plaintext passwords is a recurring theme in data breaches, and resources like Have I Been Pwned have cataloged similar incidents, underscoring the persistent vulnerability of user credentials when not adequately protected through encryption or robust password policies. The continued availability of such datasets highlights the long tail of data breach impact, where information can remain a threat vector for years post-discovery.
Breach Breakdown
9,811 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds