The Boxee Breach Exposed 104,584 U.S. Accounts and Passwords
HEROIC analysts have logged a breach affecting Boxee, the discontinued home theater PC software maker, tied to its official support forum at forums.boxee.com. The breach is dated March 28, 2014, and involves 104,584 exposed records. According to the incident record, attackers obtained the forum's entire vBulletin MySQL database and posted it for download directly on the Boxee forum itself, exposing data spread across nearly 200 database tables. The exposed data includes email addresses, usernames, IP addresses, and vBulletin password hashes.
Why an Old Forum Dump Still Poses a Risk
A decade-old forum breach might sound like old news, but the data rarely stops being useful to attackers. People reuse passwords for years, and an email and password pair pulled from a 2014 vBulletin dump can still unlock a current email, banking, or shopping account if that password was never changed. The vBulletin hashing format used at the time is also well documented and comparatively easy to crack with modern hardware, which means passwords that looked safe in 2014 are often trivial to recover today.
What Was Exposed in the Boxee Forum Breach
- Email addresses
- Usernames
- IP addresses
- Passwords stored in vBulletin hash format
Why This Matters for Boxee Forum Users
Even though Boxee itself no longer exists, the accounts tied to this breach can still cause damage. Attackers routinely feed old email and password combinations into automated credential stuffing tools, testing them against email providers, banks, and online retailers. If the password from your old Boxee account matches a password you still use anywhere else, that account is at risk of takeover. The included IP addresses can also be used to build a profile of a user's approximate location and online activity from that period.
How a Forum Database Breach Like This Happens
This incident falls into the database breach category, meaning attackers gained direct access to the site's backend database rather than tricking individual users. In cases involving forum software like vBulletin, attackers typically exploit an unpatched vulnerability or a compromised administrator account to pull the entire user table in one export. Once extracted, the whole database, usernames, hashed passwords, emails, and internal metadata included, can be copied and redistributed indefinitely, which is exactly what happened when the Boxee data was posted publicly on the forum it was stolen from.
Check If You Are Affected
If you ever created an account on the Boxee forums, or if you tend to reuse passwords across old accounts, it is worth finding out whether your information appears in this or any other breach. HEROIC's free breach scanner checks your email against a database of more than 400 billion breached records, giving you a clear answer in seconds and helping you know exactly which passwords to change.
Breach Breakdown
104,584 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds