Hacker shares data stolen on 18 companies, like Dave and Wattpad, on a forum for free, including 9 previously unreported breaches of Havenly, Indaba Music, more
Lawrence Abrams / BleepingComputer : Tweets: @haveibeenpwned and @haveibeenpwned Tweets: @haveibeenpwned : New breach: Online fragrance service Scentbird had 5.8M records breached last month. Data included email addresses, names, genders, DOBs, bcrypt password hashes and indicators of password strength. 85% were already in @haveibeenpwned. Read more: https://www.bleepingcomputer.com/ ... @haveibeenpwned : New breach: AI training data company Appen had 5.9M records breached last month and sold online. Data included names, email and IP addresses, phone numbers and bcrypt password hashes. 60% were already in @haveibeenpwned. Read more: https://www.bleepingcomputer.com/ ...
Context & Ripple Effects
This dump extends a pattern from early 2019, when a hacker listed ~617M account details from 16 hacked companies for sale on the dark web and separate actors flooded forums with 845GB of Collection #2-5 credential archives. What changed here is both scale of novelty — nine of the eighteen companies, including Havenly and Indaba Music, had never publicly confirmed a breach — and pricing: the data is being given away rather than sold.
Free distribution turns a private commodity into common infrastructure. The named services — Dave, Wattpad, plus the freshly exposed Havenly and Indaba Music — now join the ingestion pipeline that sites like Have I Been Pwned use to alert victims, the same pipeline later fed by corpora such as the Naz.API dataset.
First-order effects
- The nine previously unreported companies — Havenly and Indaba Music among them — face immediate pressure to confirm the breaches, notify users, and force password resets before their first public statement is someone else's dump.
- Customers of all eighteen services, including Dave and Wattpad, can now have their bcrypt-hashed credentials attacked without paying for access, since the forum post removes the paywall that gated the 2019 dark-web listings.
Second-order effects
- Breach-notification aggregators like Have I Been Pwned become the de facto disclosure channel, absorbing the records so victims learn of exposure from a third party rather than from the breached company itself.
- Credential-stuffing tooling gets cheaper inputs: free mega-dumps lower the marginal cost of attack below what the for-sale model sustained, pushing every consumer service with reused-password users into higher fraud-loss territory.
Third-order effects
- If hackers keep giving away stolen corpora to build reputation, the economics of breach data invert — value migrates from selling records to the attention and credibility the release buys, and corporate disclosure timelines lose meaning when anonymous forums announce breaches first.
- Aggregated free archives compound across incidents into permanent background exposure, making per-breach notification an increasingly weak defense and shifting burden toward passwordless authentication and breached-credential screening at login.
The trend: Stolen-account data is shifting from a dark-web commodity sold in bulk to free forum dumps used as reputation currency, with aggregator services absorbing disclosure duties that breached companies delay.