Data breach exposes up to 14.2M email logins at six ISPs
A data breach has compromised up to 14.2 million email login credentials from six internet service providers, exposing email addresses and passwords that were stored in plain text. The affected ISPs include several smaller providers, and the leaked data poses a significant risk for credential stuffing and account takeover attacks.
Background
- Six small US internet service providers (ISPs) — including names like EarthLink and WiMan — suffered a data breach exposing up to 14.2 million email credentials (email addresses and plaintext or weakly hashed passwords).
- The breach originated from a compromised API endpoint at a third-party data broker, not from the ISPs directly. This highlights how supply-chain data aggregation can become a single point of failure.
- Many of the leaked passwords were stored in plaintext or using MD5 (an outdated, easily reversible hash), making them trivial for attackers to crack and use for credential stuffing (trying the same email/password on other sites like banks or social media).
- The data appears to have been circulating in cybercriminal forums, increasing the risk of account takeovers, phishing, and spam campaigns targeting the affected users.