The CigReviews Leak Exposed More Users Than the Population of Pasadena, CA
HEROIC analysts uncovered the CigReviews breach while scanning dark web forums for forum database exposures. In January 2021, the now-defunct cigarette enthusiast community suffered a database compromise that occured without public disclosure, leaving 168,411 user records exposed. The leaked data included email addresses, password hashes, usernames, IP addresses, gender, birthday, and cryptographic salt values.
Why vBulletin Password Hashes With Salts Still Enable Account Takeover
Although salted vBulletin hashes are harder to crack than unsalted MD5, dedicated cracking rigs can still reverse weak or common passwords. With the salt values included in the CigReviews dump, attackers have everything they need to run targeted dictionary attacks. Combined with birthdays, genders, and IP addresses, the dataset is accessable to threat actors looking to build detailed user profiles for credential stuffing and targeted phishing campaigns against affected accounts on other platforms.
What Was Exposed in the CigReviews Breach
- Email Address
- Password Hash
- Username
- IP Address
- Gender
- Birthday
- Salt
Why Forum Breaches Are High-Value Targets for Identity Theft and Financial Fraud
Online forum members tend to use the same passwords across multiple services and share personal details freely within trusted communities. The CigReviews dataset pairs usernames with birthdays and email addresses, a combination beleived by security researchers to be particularly useful for bypassing security questions and identity verification processes at financial institutions. This creates direct pathways to account takeover and financial fraud well beyond the original forum platform.
How Database Breaches Work
A database breach occurs when an attacker gains unauthorized access to a web platform's backend data store, often by exploiting vulnerabilities in forum software like vBulletin, using stolen administrative credentials, or targeting improperly secured database interfaces. Once inside, they extract the full user table and distribute the dump on dark web marketplaces or underground forums, where it is purchased and used for downstream attacks including credential stuffing, phishing, and identity theft.
Check If Your Data Was Exposed
Run a free check with HEROIC's breach scanner, powered by over 400 billion compromised records, to see if your email address was part of the CigReviews breach or any other known data exposure. Identifying your risk early is the fastest way to protect your accounts.
Breach Breakdown
168,411 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds