If You Reused Passwords in 2016, the Craft Forum Breach Is a Risk
HEROIC analysts recieved intelligence showing that the Craft Forum database breach, which occured in September 2016, has been quietly recirculating across dark web marketplaces. The breach exposed 878 user accounts from craftsforum.co.uk, a United Kingdom-based online community for crafting and DIY enthusiasts. Although the record count is small, analysts flagged this breach as partcularly noteworthy because older forum credentials are frequently bundled into large combolists used in automated login attacks against major platforms.
Why Exposed Passwords From Old Forum Accounts Still Threaten You Today
The Craft Forum breach included password hashes stored in the vBulletin format. Older vBulletin password hashes are well-known to security researchers and attackers alike, meaning many of these passwords have likely already been cracked and converted to plain text. Attackers who obtain these credentials will run them through automated tools that test the same username and password combination across hundreds of popular websites, banking apps, and email providers. If you used the same password on Craft Forum as anywhere else, those accounts are directly at risk. The data is beleive to still be actively traded in private Telegram groups focused on older breach compilations.
What Was Exposed in the Craft Forum Breach
- Email addresses
- Usernames
- Passwords (vBulletin hashed format)
Why a Breach From 2016 Is Still a Real Threat in 2025
Many people seperate their online activity by platform but reuse the same passwords across accounts. This is exactly what credential stuffing attacks exploit. A threat actor who cracks a password from a 2016 forum breach can test it against your current email, social media, or even financial accounts within seconds using automated tools. Identity theft, account takeover, and financial fraud are all realistic outcomes when old credentials resurface. The longer a breach goes undetected or ignored, the more time attackers have to build and refine their attack lists.
How a Database Breach Works
A database breach happens when an attacker gains unauthorized access to a website's backend database, typically by exploiting a security flaw in the software or server configuration. Older community forums like Craft Forum often ran on software that had not been updated regularly, making them easier targets. Once inside, the attacker copies user records including emails and password hashes, then exits without leaving obvious traces. The stolen data is later sold or shared in underground communities, sometimes years after the original incident.
Check If Your Data Was Exposed
HEROIC's free breach scanner searches across a database of over 400 billion exposed records to tell you whether your email address or credentials have appeared in known breaches, including the Craft Forum leak. Run a free check at HEROIC.com to find out what attackers may already know about your accounts, and get personalized steps to secure them before any damage is done.
Breach Breakdown
878 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds