eon.nk
Energy
Sends you your user name and password in plain text after creating an account.

eon.nk

Energy

Sends you your user name and password in plain text after creating an account.

sog.org.uk
Genealogy
Family history association. stores address details and date of birth - thanks for keeping my personal details so safe!

sog.org.uk

Genealogy

Family history association. stores address details and date of birth - thanks for keeping my personal details so safe!

gaschecker.co.uk
Certification

gaschecker.co.uk

Certification

gadgetsonline.co.nz
Gadgets

gadgetsonline.co.nz

Gadgets

voetbalzone.nl
Football news
Stores password in plain text.
This is an email I received after clicking ‘forgot password’ on their website.

voetbalzone.nl

Football news

Stores password in plain text.

This is an email I received after clicking ‘forgot password’ on their website.

online.nl
Dutch ISP
A customer has an account with them to access their email account and some settings. Sadly, when you forget your password, and decide to recover it, they send you a plaintext password per email.

online.nl

Dutch ISP

A customer has an account with them to access their email account and some settings. Sadly, when you forget your password, and decide to recover it, they send you a plaintext password per email.

worth1000.com, designcrowd.com
Graphics design marketplace
On the first day of taking over Worth1000, they spam me ignoring my email preferences, and send me my password in the clear.

worth1000.com, designcrowd.com

Graphics design marketplace

On the first day of taking over Worth1000, they spam me ignoring my email preferences, and send me my password in the clear.

damn.com
Video sharing
After registering

damn.com

Video sharing

After registering

cellarmasters.com.au
Wine retailer
After selecting password recovery.

cellarmasters.com.au

Wine retailer

After selecting password recovery.

pixabay.com
Stock photos
Their “Forgot password” function only asks for an e-mail, and once that’s entered, you’ll get plaintext credentials over unsecured HTTP. ugh.

pixabay.com

Stock photos

Their “Forgot password” function only asks for an e-mail, and once that’s entered, you’ll get plaintext credentials over unsecured HTTP. ugh.