---
title: "BreachForums user-database exposure"
description: "Evidence-backed account of BreachForums user-database exposure, covering what happened, impact, timeline, attack vector, technical details, and primary sources."
incident_type: "Data incident"
status: "active"
last_modified: "2026-08-09"
canonical_url: "https://www.ally.security/incidents/breachforums-user-database-exposure-2025"
markdown_url: "https://www.ally.security/incidents/breachforums-user-database-exposure-2025.md"
stix_url: "https://www.ally.security/incidents/breachforums-user-database-exposure-2025/stix.json"
---

# BreachForums user-database exposure

A backup of the breachforums.hn MyBB user table and forum signing-key material was exposed and later released publicly. The public corpus included a MyBB user table; HIBP separately cataloged unique email addresses across user, post, and private-message tables.

Last modified Aug 9, 2026 · 2 sources

## Summary

- **Environment:** Not publicly identified
- **Operational impact:** No outage or recovery duration quantified
- **Financial impact:** No public cost estimate

## What happened

A backup of the [breachforums.hn](https://breachforums.hn/) MyBB user table and forum signing-key material was exposed and later released publicly. [1](#source-1)

## Impact

The public corpus included a MyBB user table; HIBP separately cataloged unique email addresses across user, post, and private-message tables. [1](#source-1) [2](#source-2)

Documented data types include:

- Message content — Forum posts and private messages represented in the broader HIBP corpus. [1](#source-1) [2](#source-2)
- Contact information — Email addresses represented in the HIBP corpus. [1](#source-1) [2](#source-2)
- IP addresses — IP addresses in the MyBB users table; most used a loopback value, while 70,296 rows did not. [1](#source-1) [2](#source-2)
- Usernames and account identifiers — Usernames and member display names in the user table. [1](#source-1) [2](#source-2)
- Account credentials — HIBP lists passwords and describes the user-table passwords as Argon2 hashes; this claim does not assert plaintext credentials. [1](#source-1) [2](#source-2)

A cited record reports 672,247 records (Unique email addresses represented across the HIBP corpus's user, forum-post, and private-message tables; not an affected-individual count; as of 2026-01-10). [1](#source-1) [2](#source-2)

A cited record reports 323,988 records (Rows in the directly inspected MyBB users table; not a count of unique people or all records in the broader HIBP corpus). [1](#source-1)

A cited record reports 70,296 records (MyBB user-table rows that did not use the common loopback address; BleepingComputer said the tested values mapped to public IP addresses. This is not a unique-person count). [1](#source-1)

The exposed signing-key file was passphrase-protected when BleepingComputer first analyzed it; the repository does not retain the key or any password later reported for it. [1](#source-1)

## Timeline

### August 11, 2025 — Documented event

HIBP BreachDate and the last registration date in the leaked user table. The administrator described an August 2025 exposure but did not publicly establish the exact download date. [1](#source-1) [2](#source-2)

### January 9, 2026 — Public disclosure

Date the archive was publicly released, based on BleepingComputer's January 10 report describing the release as occurring the previous day. [1](#source-1)

### August 9, 2026 — Briefing updated

This briefing was last reviewed and updated on August 9, 2026.

## Threat Group & Attack Vector

The cited public record does not establish a specific initial-access vector, malware family, exploited vulnerability, or ATT\&CK technique.

### Actors

- No threat actor group has been identified in the reviewed public evidence.

### TTPs

- No specific MITRE ATT\&CK technique is currently mapped for this case.

## Response

A publicly released archive contained the MyBB user-table SQL dump, text about the release, and the forum's PGP private-key file. The current forum administrator acknowledged that an old MyBB user-table backup and the forum PGP key had been temporarily stored in an unsecured folder and said the folder was downloaded once. No access path, attribution, scale, or recovery detail is inferred beyond the cited claims. [1](#source-1)

## Assets

[Download the case-scoped STIX 2.1 bundle](<https://www.ally.security/incidents/breachforums-user-database-exposure-2025/stix.json>)

## Sources

Primary source records used to research this incident.

<a id="source-1"></a>

### BreachForums hacking forum database leaked, exposing 324,000 accounts

news · BleepingComputer · Jan 10, 2026

<https://www.bleepingcomputer.com/news/security/breachforums-hacking-forum-database-leaked-exposing-324-000-accounts/>

<a id="source-2"></a>

### BreachForums (2025) breach record

advisory · Have I Been Pwned · Jan 10, 2026

<https://haveibeenpwned.com/api/v3/breach/BreachForums2025>

<details>
<summary>Evidence ledger</summary>

Review the supporting structured claims.

1. **Exposed Record Count · 100% confidence · current**  
   BreachForums user and message-data exposure: 672,247 record
2. **Disclosed At · 90% confidence · current**  
   2025 BreachForums user-database exposure: 2026-01-09
3. **Exposed Data Category · 100% confidence · current**  
   BreachForums user and message-data exposure: Message content
4. **Exposed Data Category · 100% confidence · current**  
   BreachForums user and message-data exposure: Contact information
5. **Occurred At · 80% confidence · current**  
   2025 BreachForums user-database exposure: 2025-08-11
6. **Affected Organization · 100% confidence · current**  
   2025 BreachForums user-database exposure: BreachForums (.hn iteration)
7. **Resulted In · 100% confidence · current**  
   BreachForums user and message-data exposure: A publicly released archive contained the MyBB user-table SQL dump, text about the release, and the forum's PGP private-key file.
8. **Exposed Data Category · 100% confidence · current**  
   BreachForums user and message-data exposure: IP addresses
9. **Exposed Data Category · 100% confidence · current**  
   BreachForums user and message-data exposure: Usernames and account identifiers
10. **Resulted In · 100% confidence · current**  
   BreachForums user and message-data exposure: The exposed signing-key file was passphrase-protected when BleepingComputer first analyzed it; the repository does not retain the key or any password later reported for it.
11. **Resulted In · 100% confidence · current**  
   2025 BreachForums user-database exposure: BreachForums user and message-data exposure
12. **Resulted In · 90% confidence · current**  
   2025 BreachForums user-database exposure: The current forum administrator acknowledged that an old MyBB user-table backup and the forum PGP key had been temporarily stored in an unsecured folder and said the folder was downloaded once.
13. **Exposed Data Category · 100% confidence · current**  
   BreachForums user and message-data exposure: Account credentials
14. **Exposed Record Count · 100% confidence · current**  
   BreachForums user and message-data exposure: 323,988 record
15. **Exposed Record Count · 100% confidence · current**  
   BreachForums user and message-data exposure: 70,296 record

</details>
