yaLOG!
We noticed a recent surge in credential stuffing attempts targeting services frequented by radio hobbyists, prompting an investigation into potential data exposures within that community. Our analysis led us to a data dump surfaced on a prominent hacking forum on August 26, 2018, attributed to a breach of yaLOG!, a Dutch software suite catering to 11-meter (CB) radio band enthusiasts. What struck us was the relatively small scale of the exposure, impacting only 1,677 users, yet the inclusion of both bcrypt and phpass password hashes suggests a deliberate effort to capture usable credentials. The nature of the data, combined with the forum's reputation for facilitating such attacks, indicates a clear intent to leverage these credentials for further malicious activities.
The breach of yaLOG! data, discovered on August 26, 2018, involved the exposure of 1,677 records. The leaked information comprised email addresses and password hashes, specifically in both bcrypt and phpass formats. This suggests a database compromise where user authentication data was exfiltrated. The inclusion of multiple hashing algorithms is noteworthy, as it could indicate an older system that was either not fully upgraded or had multiple authentication mechanisms. The primary threat theme here is the potential for credential stuffing and account takeover. Attackers can use these email/password pairs to attempt logins on other popular online services, exploiting the common practice of password reuse. The source structure points to a direct database extraction, and the leak location was a well-known underground forum.
While this specific yaLOG! breach did not generate widespread mainstream news coverage at the time of its discovery in 2018, its implications resonate with ongoing trends in cybercrime. The use of compromised credentials from niche communities, like radio hobbyists, is a common tactic. OSINT investigations into similar data dumps often reveal patterns where attackers aggregate credentials from various sources to build comprehensive combolists. Research from cybersecurity firms consistently highlights the pervasive threat of credential stuffing, with millions of login attempts occurring daily across the internet. This incident serves as a reminder that even seemingly small or specialized platforms can become targets, and their compromised data can fuel broader cybercriminal operations.
Breach Breakdown
1,677 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds