The server where Adobe and PR Newswire data was found by experts apparently also stored the stolen files from the systems of the online dating service Cupid Media.
Researcher Brian Krebs has discovered a database containing the email addresses, passwords, names, and birth dates of over 42 million Cupid Media users. Unfortunately, all of the passwords are in plain text.
The attack on Cupid Media likely took place in January 2013. At the time, the company notified a select group of affected users to reset their passwords. However, the incident was not disclosed to the public.
The company's CEO, Andrew Bolton, told Krebs that after discovering the breach, it hired a firm to implement additional security measures, such as encrypting passwords. They've also implemented new rules to make sure users use strong passwords.
Bolton claims that many of the files stored in the database stolen by the hackers are old, inactive, or deleted. However, he promised that the company will investigate the incident further based on this new information.
After the discovery of Kerbs, the company initiated a double-check to ensure that affected customers had reset their passwords and received warning messages.
The most popular non-numeric passwords are “iloveyou,” “lovely,” “qwerty,” “password,” “AZERTY,” “loveme,” “aaaaaa,” “MyLove,” “iloveu,” and “zxcvbnm.”
Most of the exposed email addresses are from Yahoo, Hotmail, and Gmail. However, 56 belong to Department of Homeland Security personnel, 11,508 to U.S. military personnel, and 9,844 to U.S. government employees.

