/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

Hacker shares data stolen on 18 companies, like Dave and Wattpad, on a forum for free, including 9 previously unreported breaches of Havenly, Indaba Music, more

Lawrence Abrams / BleepingComputer : Tweets: @haveibeenpwned and @haveibeenpwned Tweets: @haveibeenpwned : New breach: Online fragrance service Scentbird had 5.8M records breached last month. Data included email addresses, names, genders, DOBs, bcrypt password hashes and indicators of password strength. 85% were already in @haveibeenpwned. Read more: https://www.bleepingcomputer.com/ ... @haveibeenpwned : New breach: AI training data company Appen had 5.9M records breached last month and sold online. Data included names, email and IP addresses, phone numbers and bcrypt password hashes. 60% were already in @haveibeenpwned. Read more: https://www.bleepingcomputer.com/ ...

BleepingComputer Lawrence Abrams

Context & Ripple Effects

This dump extends a pattern from early 2019, when a hacker listed ~617M account details from 16 hacked companies for sale on the dark web and separate actors flooded forums with 845GB of Collection #2-5 credential archives. What changed here is both scale of novelty — nine of the eighteen companies, including Havenly and Indaba Music, had never publicly confirmed a breach — and pricing: the data is being given away rather than sold.

Free distribution turns a private commodity into common infrastructure. The named services — Dave, Wattpad, plus the freshly exposed Havenly and Indaba Music — now join the ingestion pipeline that sites like Have I Been Pwned use to alert victims, the same pipeline later fed by corpora such as the Naz.API dataset.

First-order effects

  • The nine previously unreported companies — Havenly and Indaba Music among them — face immediate pressure to confirm the breaches, notify users, and force password resets before their first public statement is someone else's dump.
  • Customers of all eighteen services, including Dave and Wattpad, can now have their bcrypt-hashed credentials attacked without paying for access, since the forum post removes the paywall that gated the 2019 dark-web listings.

Second-order effects

  • Breach-notification aggregators like Have I Been Pwned become the de facto disclosure channel, absorbing the records so victims learn of exposure from a third party rather than from the breached company itself.
  • Credential-stuffing tooling gets cheaper inputs: free mega-dumps lower the marginal cost of attack below what the for-sale model sustained, pushing every consumer service with reused-password users into higher fraud-loss territory.

Third-order effects

  • If hackers keep giving away stolen corpora to build reputation, the economics of breach data invert — value migrates from selling records to the attention and credibility the release buys, and corporate disclosure timelines lose meaning when anonymous forums announce breaches first.
  • Aggregated free archives compound across incidents into permanent background exposure, making per-breach notification an increasingly weak defense and shifting burden toward passwordless authentication and breached-credential screening at login.

The trend: Stolen-account data is shifting from a dark-web commodity sold in bulk to free forum dumps used as reputation currency, with aggregator services absorbing disclosure duties that breached companies delay.

Discussion

  • @haveibeenpwned @haveibeenpwned on x
    New breach: Online fragrance service Scentbird had 5.8M records breached last month. Data included email addresses, names, genders, DOBs, bcrypt password hashes and indicators of password strength. 85% were already in @haveibeenpwned. Read more: https://www.bleepingcomputer.com/ …
  • @haveibeenpwned @haveibeenpwned on x
    New breach: AI training data company Appen had 5.9M records breached last month and sold online. Data included names, email and IP addresses, phone numbers and bcrypt password hashes. 60% were already in @haveibeenpwned. Read more: https://www.bleepingcomputer.com/ ...