Data breach
corevin.com
- Records
- 732,504
- Breach date
- 1 January 2020Estimated
- Added
- 1 December 2024
What was exposed
2 types of data · 1 puts you at serious risk
- Email addresses732,504
- Passwords731,910
About this breach
The investigation team has indexed a listing for corevin.com containing 732,504 records, most of them email addresses paired with passwords. The team estimates the breach occurred around January 1, 2020. No hacker or group has claimed responsibility for the underlying incident. Public information about the site itself and the circumstances of the breach is scarce, but the record has a traceable path into circulation: in July 2020, a hacker published a list of more than 8,200 databases stolen from DataViper, a data leak monitoring service operated by US security researcher Vinny Troia, and corevin.com appears by name among the database samples in that list, as documented by ZDNet. The hacker emailed reporters a link to a dark web portal describing the intrusion and posted samples from hundreds of the databases held on DataViper's servers. ZDNet reported at the time that most of the listed databases came from older, previously known breaches, and Troia disputed the hacker's account, saying the attacker had only reached a test server. Whether the corevin.com records originated from an intrusion into the site itself or from a database circulating among hacker communities was not established in available reporting.
Limited public reporting: As of September 25, 2026, detailed company notices or major news coverage for this listing were limited in sources reviewed. The facts below rely primarily on the indexed fields plus any secondary sources cited.
What Information Was Compromised?
Our analysis found the following data types in this breach: email addresses and passwords. Nearly every record in the listing includes a password: 731,910 of the 732,504 rows contain one.
Not every individual is affected by every type of data listed here.
The listing does not indicate whether passwords were stored as plain text, encrypted, or as hashes, and the original corevin.com service has not published any notice about the incident in the sources reviewed as of September 25, 2026.
What Are the Potential Risks for Affected Individuals?
Exposed email and password pairs are primarily valuable for credential stuffing. Attackers feed leaked passwords into login pages for email providers, banks, shopping sites, and social networks, on the assumption that people reuse the same password across accounts. Because email addresses are the recovery point for most other online accounts, access to an inbox can cascade into password resets and account takeovers elsewhere.
The records may also be used for targeted phishing. A message that knows your email address appears more credible, and a database of hundreds of thousands of addresses is routinely resold and redistributed long after the initial leak, which is why the risks do not expire with time.
What Should You Do If You Were Affected?
If your email appears in this listing, take these steps:
Change your password anywhere you used the compromised one, starting with your primary email account. Use a unique password for every service.
Enable two-factor authentication on your important accounts, especially email and banking. A second factor blocks most account takeovers even when the password is known.
Watch for phishing. Be suspicious of unexpected emails asking you to log in, verify an account, or follow a link.
Use a password manager so that every account gets a strong, distinct password going forward.
Changing a password that has already leaked does not undo the exposure, but it prevents that credential from being used against you in the future. The records in this listing have circulated alongside a large collection of older breach data, so reviewing your accounts for unusual login activity is also a reasonable precaution.
