The BoostBot Leak Exposed 163,958 US-Based Software Accounts
HEROIC analysts identified 163,958 exposed accounts tied to BoostBot, a U.S.-based software platform breach dated December 31, 2014. The exposed data includes IP addresses, email addresses, usernames, passwords, and hash type information, giving attackers a fairly complete picture of each affected account.
Why the BoostBot Leak Puts Accounts at Risk
The passwords in this breach were hashed using the MyBB format, a scheme used by MyBB forum software at the time. Like many older hashing algorithms, MyBB hashes can be cracked with modern computing power, turning what looks like protected data into plain text passwords. Combined with IP addresses, email addresses, and usernames, this gives attackers enough detail to attempt logins elsewhere and, in some cases, narrow down a user's general location.
What Was Exposed in the BoostBot Breach
- IP addresses
- Email addresses
- Usernames
- Passwords (MyBB hash format)
Why This Matters for BoostBot Users
If you ever created a BoostBot account, the odds that you reused that password somewhere else are real, and that's exactly what attackers count on. Automated credential stuffing tools take leaked email and password pairs and test them against banking sites, email providers, and social media platforms. Any account still using a BoostBot password remains at risk today.
How This Database Breach Happened
This incident is classified as a database breach, meaning attackers gained direct access to BoostBot's user database rather than collecting data through malware. Sites running MyBB forum software during this period were frequently targeted through unpatched vulnerabilities or stolen administrator credentials. Once inside, attackers can export the entire user table, capturing IP addresses, emails, usernames, and hashed passwords for all 163,958 accounts in a single file.
Check If You Are Affected by the BoostBot Breach
You don't need to guess whether your information was part of the BoostBot breach or any other leak. HEROIC's free breach scanner checks your email address against a database of more than 400 billion leaked records and shows you exactly what was exposed. If you find a match, change the password on any account still using it and enable multi-factor authentication where you can.
Breach Breakdown
163,958 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds