Skip to main content

The Leak in the List

Overview


Room URL: https://tryhackme.com/room/adventofcyberpreptrack
Difficulty: Easy
Category: Prep
Date Completed: 12/1/2025

Objective

Check if McSkidy’s email has appeared in a breach.


Table of Contents

Introduction
Walk Through
Lessons Learned
Resources


Introduction

Rumors circulate that TBFC's data has been leaked, causing emails to bounce and staff to panic. McSkidy suspects his account may have been compromised in the breach. Defenders use tools like Have I Been Pwned to identify compromised accounts early, preventing attacks from spreading further.


Walk Through

  1. Click the view site button to launch the simulated Have I Been Pwned website
  2. Enter McSkiddy's email [email protected] to see if it has been compromised
  3. The email has been found in a breach
    1. hopsec.io compromised on 2025-01-16 LeakList.png

Lessons Learned

  • Learned how to use Have I Been Pwned to check if email addresses have been compromised in data breaches
  • Successfully identified that McSkidy's email [email protected] was compromised in the hopsec.io breach on 2025-01-16, demonstrating the importance of early breach detection

Resources

TryHackMe
HaveIBeenPwned