Dark Web Intel: Fight Site Database Dump Exposed 942 Passwords
HEROIC analysts identified the Fight Site breach while monitoring dark web forums and Telegram channels known for trading aged database dumps. The Croatian combat sports platform fightsite.hr was hit on November 1, 2016, with 942 user records extracted from its vBulletin database. What recieved little attention at the time of the original breach has since resurfaced repeatedly in credential compilation archives, placing affected users at continued risk nearly a decade later.
How vBulletin Password Hashes Enable Credential Stuffing at Scale
The vBulletin password format used by Fight Site is seperate from modern hashing standards and is considered weak by current security benchmarks. Attackers with GPU cracking hardware can process thousands of vB hashes per second offline, with no rate limiting or lockout to stop them. Once cracked, those credentials are fed into automated stuffing tools that test them against email accounts, sports betting platforms, gaming sites, and anywhere else the same user may have registered.
What Was Exposed in the Fight Site Breach
- vBulletin password hashes (vB format)
- User account records
- 942 total records from the fightsite.hr database
Why Sports Forum Credentials Are Targeted for Account Takeover
Combat sports and martial arts communities often have significant overlap with sports betting platforms, pay-per-view streaming services, and merchandise accounts. Credential stuffing campaigns against Fight Site users are partcularly attractive to threat actors because cracked passwords may open doors to accounts with stored payment methods and higher value assets. Identity theft and financial fraud are real downstream risks from what appears to be a small niche forum breach.
How Database Breaches Work
A database breach happens when an attacker finds and exploits a weakness in a website's backend, such as an outdated content management system, a SQL injection vulnerability, or poorly secured server access. vBulletin-powered forum sites were a frequent target in the mid-2010s because known vulnerabilities circulated widely in attacker communities. Once the database is copied, it is typically sold privately before eventually being published to open forums where it circulates indefinitely.
Check If Your Data Was Exposed
HEROIC's free breach scanner searches more than 400 billion records, including dark web dumps like the Fight Site database that continue to circulate in compilation archives. Check now to see if your credentials were exposed, and get clear steps to protect your accounts from credential stuffing attacks before your data is used against you.
Breach Breakdown
942 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds