Pemiblanc 2018.0 Data Breach

Pemiblanc Credential Stuffing List: 111M Email & Password Pairs Aggregated from Multiple Breaches | ObscureIQ
ObscureIQ Breach Intelligence

Classification Tags

UnknownScraping / CollectionBreach CompilationEmail AddressPassword
Low SeverityCredential combolist

Pemiblanc Credential Stuffing List: 111M Email & Password Pairs Aggregated from Multiple Breaches

Aggregated stolen credentials and password pairs.

Verified by ObscureIQ Intelligence
27/100Breach Risk Index
17Data Value
10Market Recency
2921dSince Breach

Breach Intelligence Summary

Entity: Pemiblanc · Actor: Unknown (aggregator) · Sources: 9 references
Attack: Scraping / Collection
Profile: Breach Compilation · Aggregated stolen credentials and password pairs · Credential stuffing list · Global
Timeline: Breach (2018-04-02) · Indexed (Jul 09, 2018) · Year (2018.0)
Exposure: 111.0M records · 2 fields: Email Address, Password
Status: Compilation

Executive Summary

In April 2018, a credential-stuffing list dubbed "Pemiblanc" was found on a French server, containing 111 million email address and password pairs consolidated from various data breaches. About 94% of the addresses were already in HIBP, with roughly 6.8 million new. It is an aggregated list built for account-takeover attacks.

ObscureIQ assessment: High risk of account takeover and credential stuffing. The main danger is direct operational usefulness for attackers testing reused credentials at scale.

Breach Impact

As an aggregated credential-stuffing list, it is directly usable for automated account-takeover; presence indicates a credential is circulating, not that a specific site was breached.

About Pemiblanc

Pemiblanc is the name given to a credential-stuffing list discovered on a French server, aggregating credentials from many prior breaches, not a breach of a single organization.

Why They Hold Your Data

Credential-stuffing lists collect and normalize stolen usernames, emails, and password pairs from multiple earlier exposures into one reusable dataset.

Data Points Exposed

2 verified field types
Email Address
Password Critical

Field names are shown in full for clarity and search visibility. Canonical machine keys are emitted only in this page’s structured data.

Exploitation & Downstream Threats

Threat Activity:Moderate
Primary downstream threats:
  • Credential stuffing against reused passwords across other platforms
  • Targeted phishing campaigns using exposed email addresses
Threat vectors:
  • Phishing, credential stuffing & account takeover
  • Credential stuffing & account takeover

Threat Actor: Unknown (aggregator)

Unknown (aggregator)
Scraping / Collection

Attribution and method are based on available breach intelligence. Reported attack vector: Scraping / Collection.

Recommended Actions

If you believe your information may be included:

Change Reused Passwords
Update this account and anywhere you reused the password; use a manager.
Enable MFA Everywhere
Turn on multi-factor authentication on email first, then financial accounts.
Report & Recover
If you spot misuse, start an official recovery plan and report fraud.

Frequently Asked Questions

What happened in the Pemiblanc breach?

In April 2018, a credential-stuffing list dubbed "Pemiblanc" was found on a French server, containing 111 million email address and password pairs consolidated from various data breaches. About 94% of the addresses were already in HIBP, with roughly 6.8 million new. It is an aggregated list built…

What data was exposed?

Verified fields include Email Address, Password.

What should I do if I was affected?

Change reused passwords, enable MFA, and (if identity or financial data is involved) freeze your credit and monitor your accounts.

Sources & References

Every claim on this page is traceable. This breach draws on:

Breach Index
Have I Been Pwned
Record & field corroboration
Breach Index
DataBreach.com
Record & field corroboration
Cross-source
9ghz
Independent catalogue listing
Cross-source
BreachAware
Independent catalogue listing
Cross-source
BreachForums_Official_Index
Independent catalogue listing
Cross-source
DataViper.io
Independent catalogue listing
Cross-source
Dehashed
Independent catalogue listing
Cross-source
leakfind
Independent catalogue listing
ObscureIQ Intelligence
ObscureIQ proprietary analysis
Risk Index scoring & downstream-threat assessment

Protect Yourself

Check If You're Affected

Enter your email to check whether your data appears in this breach. We’ll send a 6-digit code to confirm it’s your address.

Get Free Breach Alerts

Be the first to know when new breaches are disclosed. Free forever — confirm your email with a 6-digit code.

High-Risk? Get an Exposure Audit

Executives, public figures, and high-visibility operators can receive tailored exposure intelligence and hardening guidance.

Request Consultation