BigBigForums_com
We've been tracking a resurgence of older forum breaches appearing in aggregated credential stuffing lists. While the individual impact of these breaches may seem limited due to their age, the cumulative effect of password reuse across numerous platforms poses a significant risk. Our team identified a large set of credentials linked to **BigBigForums.com**, a breach dating back to **December 31, 2015**. What really struck us wasn't the scale of this breach - a relatively modest **31,275** accounts - but the detailed nature of the exposed data and the continued presence of these credentials in modern password dumps. The persistence of these older credentials highlights the long tail of risk associated with legacy breaches.
The BigBigForums Breach: A Legacy of Reused Passwords
The BigBigForums.com breach, occurring on **December 31, 2015**, resulted in the exposure of **31,275** user records. The data set, labelled "BigBigForums com VB January 2016," suggests a potential leak of the forum's vBulletin database around that timeframe. The breach included sensitive information, such as usernames, email addresses, IP addresses, password hashes, and salts. This combination of data offers attackers a significant advantage in cracking passwords and potentially pivoting to other accounts where users have reused their credentials.
The breach was initially reported and indexed by various data breach monitoring services shortly after its occurrence. However, its continued relevance stems from the ongoing practice of credential stuffing, where attackers use lists of compromised credentials to attempt unauthorized access to other online services. The fact that these credentials are still circulating suggests that many users have not updated their passwords across all their accounts since the 2015 breach.
This breach matters to enterprises because it underscores the enduring risk of password reuse. Even seemingly small or outdated breaches can serve as valuable resources for attackers seeking to compromise corporate accounts or gain access to sensitive data. The availability of password hashes and salts from this breach allows attackers to conduct offline cracking attempts, potentially revealing plaintext passwords that can then be used to access corporate VPNs, email accounts, or other critical systems.
This incident ties into broader threat themes related to credential harvesting and the automation of attacks. Attackers often aggregate data from multiple breaches to create massive credential lists, which are then used in automated credential stuffing campaigns. The persistence of these older credentials in modern password dumps highlights the need for enterprises to implement robust password management policies, including mandatory password resets and the use of multi-factor authentication.
- Total records exposed: 31,275
- Types of data included: Username, Email, IP Address, Password Hash, Salt
- Source structure: Likely a database export, given the presence of usernames, emails, and password hashes.
- Leak location(s): Commonly found in aggregated credential dumps across various platforms, including dark web forums and Telegram channels.
- Date of first appearance: December 31, 2015
External Context & Supporting Evidence
While specific news coverage of the BigBigForums breach is limited due to its age, its presence in aggregated breach databases is well-documented. Security researchers and threat intelligence analysts frequently monitor these databases for compromised credentials that can be used to target enterprises. Discussions on security forums and Reddit often highlight the importance of monitoring for compromised credentials and implementing proactive measures to mitigate the risk of credential stuffing attacks.
For example, posts on Reddit's r/cybersecurity and similar subreddits often discuss strategies for identifying and mitigating the risk of credential stuffing, including the use of password monitoring services and the implementation of multi-factor authentication. These discussions underscore the ongoing relevance of older breaches in the context of modern cyber threats.
Breach Breakdown
31,275 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds