BreachForums user-database exposure

A backup of the breachforums.hn MyBB user table and forum signing-key material was exposed and later released publicly. The public corpus included a MyBB user table; HIBP separately cataloged unique email addresses across user, post, and private-message tables.

Last modified

Summary

  • Environment: Not publicly identified
  • Operational impact: No outage or recovery duration quantified
  • Financial impact: No public cost estimate
  • Record status: Developing record. Reviewed August 9, 2026; updated as evidence emerges.

What happened

A backup of the breachforums.hn MyBB user table and forum signing-key material was exposed and later released publicly. [1]

Impact

The public corpus included a MyBB user table; HIBP separately cataloged unique email addresses across user, post, and private-message tables. [1][2]

Documented data types include:

  • Message content — Forum posts and private messages represented in the broader HIBP corpus. [1][2]
  • Contact information — Email addresses represented in the HIBP corpus. [1][2]
  • IP addresses — IP addresses in the MyBB users table; most used a loopback value, while 70,296 rows did not. [1][2]
  • Usernames and account identifiers — Usernames and member display names in the user table. [1][2]
  • Account credentials — HIBP lists passwords and describes the user-table passwords as Argon2 hashes; this claim does not assert plaintext credentials. [1][2]

A cited record reports 672,247 records (Unique email addresses represented across the HIBP corpus’s user, forum-post, and private-message tables; not an affected-individual count; as of 2026-01-10). [1][2]

A cited record reports 323,988 records (Rows in the directly inspected MyBB users table; not a count of unique people or all records in the broader HIBP corpus). [1]

A cited record reports 70,296 records (MyBB user-table rows that did not use the common loopback address; BleepingComputer said the tested values mapped to public IP addresses. This is not a unique-person count). [1]

The exposed signing-key file was passphrase-protected when BleepingComputer first analyzed it; the repository does not retain the key or any password later reported for it. [1]

Timeline

  1. Documented event

    HIBP BreachDate and the last registration date in the leaked user table. The administrator described an August 2025 exposure but did not publicly establish the exact download date.

    [1][2]
  2. Public disclosure

    Date the archive was publicly released, based on BleepingComputer’s January 10 report describing the release as occurring the previous day.

    [1]
  3. Briefing updated

    This briefing was last reviewed and updated on August 9, 2026.

Threat Group & Attack Vector

The cited public record does not establish a specific initial-access vector, malware family, exploited vulnerability, or ATT&CK technique.

Actors

  • No threat actor group has been identified in the reviewed public evidence.

TTPs

  • No specific MITRE ATT&CK technique is currently mapped for this case.

Response

A publicly released archive contained the MyBB user-table SQL dump, text about the release, and the forum’s PGP private-key file. The current forum administrator acknowledged that an old MyBB user-table backup and the forum PGP key had been temporarily stored in an unsecured folder and said the folder was downloaded once. No access path, attribution, scale, or recovery detail is inferred beyond the cited claims. [1]