The BrisbaneBBs Breach Gave Hackers 317K Passwords to Crack
HEROIC analysts found the BrisbaneBBs (Ozyoyo.com) database circulating on underground forums, dated 16 February 2021. The Australian online forum, serving a Chinese-speaking community in the Brisbane and Queensland region, suffered a database breach that occured exposing 317,193 records including email addresses, usernames, MD5-salted password hashes, and IP addresses.
Why MD5 Password Hashes From the BrisbaneBBs Breach Are Easily Cracked
MD5 is a weak hashing algorithm that has been considered insecure for over a decade. Even with salting, MD5 hashes are accessable to cracking tools using modern GPUs, meaning attackers with the BrisbaneBBs dump can recover plain-text passwords at scale. Those recovered passwords can then be used in credential stuffing attacks against email accounts, banking platforms, and other online services used by affected members.
What Was Exposed in the BrisbaneBBs (Ozyoyo.com) Breach
- Email Address
- Password Hash
- Username
- IP Address
- Salt
Why the BrisbaneBBs Breach Is a Targeted Risk for 317K Forum Members
IP addresses in the dump allow attackers to geolocate affected individuals in the Brisbane area, making targeted phishing and social engineering attacks partcularly effective. Combined with email addresses and crackable passwords, this breach creates conditions for account takeover, credential stuffing across other platforms, and identity theft. Forum members who recieved no notification and have not updated passwords on connected accounts remain at ongoing risk.
How a Database Breach Works
A database breach occurs when an attacker gains unauthorized access to a forum or platform's stored user records. In cases like BrisbaneBBs, outdated password hashing practices such as MD5 make the damage significantly worse, as attackers can crack the hashes rather than simply collecting email addresses. The data is then traded or sold on underground forums.
Check If Your Data Was Exposed
HEROIC's free breach scanner searches 400 billion-plus compromised records, including the BrisbaneBBs (Ozyoyo.com) breach. Check if your email address appeared in this or any other known data leak at HEROIC.com.
Breach Breakdown
317,193 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds