Latin American social media site Taringa hacked; LeakBase says stolen database has 28M accounts with hashed passwords, of which 93.79% have been cracked so far
Mohit Kumar / The Hacker News :
Context & Ripple Effects
The Taringa breach follows a now-familiar arc for older social platforms: a stolen database surfaces years after the fact, and its weakly hashed passwords fall almost immediately. When the 2012 Last.fm hack was dumped, 96% of its 43.57M hashed passwords were cracked within two hours, and Ars Technica had already explained how the full LinkedIn password dump would speed the cracking of hashed passwords from any future breach.
What makes this report notable is who is doing the cracking: LeakBase, described as one of the world's largest cybercrime hubs with more than 142,000 members, is publishing progress on the 28M-account Taringa database in near-real time — turning password recovery into a public scoreboard rather than a private sale.
First-order effects
- Taringa's 28M users are exposed to immediate credential-stuffing attacks, since 93.79% of the hashed passwords have reportedly been recovered in plaintext.
- Taringa must force mass password resets and re-secure accounts, while its Latin American user base becomes the direct target pool for LeakBase's members.
Second-order effects
- Cracked Taringa passwords will be tested against email and other services where users reused credentials, extending the blast radius well beyond the platform itself.
- LeakBase's public progress reporting pressures rival leak venues — the same dynamic seen when the Cracked.to database was posted at Raidforums — commoditizing stolen databases instead of keeping them exclusive.
Third-order effects
- If legacy social platforms' old password hashes keep falling at this rate, the industry's real defense shifts from breach prevention to per-user mitigations: unique passwords, breached-password screening, and multi-factor authentication.
- Dedicated leak marketplaces like LeakBase are structuring the trade in stolen credentials around membership communities, making bulk credential data a persistent, distributed commodity rather than a one-off sale.
The trend: Old breaches with weakly hashed passwords are being systematically cracked and monetized through organized leak forums, so every legacy database is effectively a live credential source.