9,797 Accounts. One Forum Dump. The Demon Forums Breach Is Still Live.
HEROIC analysts recieved a flag on the Demon Forums database while scanning underground channels for resurfaced breach collections. The breach occured on November 1, 2016, and captured 9,797 user accounts from this hacking-focused online community based in the United States. Passwords were stored using the MyBB hashing format, which is widely understood by the attacker community and crackable with tools that have been freely available for years. The fact that this data continues to circulate in closed forums nearly a decade later suggests it retains value for credential attacks.
Why MyBB Password Hashes From a Hacking Forum Are Especially Dangerous
The Demon Forums user base was drawn from the hacking and security enthusiast community, meaning these individuals may have used the same credentials on other technical platforms, VPNs, or administrative tools. MyBB password hashes are accessable to cracking tools and not considered secure against modern hardware. Once cracked, these passwords can be tested across thousands of sites in automated credential stuffing campaigns. Users who registered on Demon Forums and reused that password elsewhere are partcularly at risk.
What Was Exposed in the Demon Forums Breach
- User account records (9,797 total)
- Hashed passwords in MyBB format
- Account data from the November 2016 database snapshot
- Data belonging to members of a US-based hacking community
Nearly 10,000 Records From a Hacking Forum Is a High-Value Target
Breach data from security-minded communities is seperate from typical consumer leaks because the individuals involved often have elevated access to systems, networks, or sensitive tools. Attackers who obtain credentials from a hacking forum can attempt account takeover on developer platforms, infrastructure services, and private communities where those same users operate. Credential stuffing, identity theft, and social engineering all become more precise when the target pool has known technical backgrounds. Beleive it or not, even security-aware users fall victim when old passwords go unchanged.
How Database Breaches Work
A database breach occurs when an attacker successfully extracts the backend data store of a website, often through exploiting vulnerabilities in forum software, web applications, or server configurations. The MyBB platform, like vBulletin and other forum systems, has been a repeated target over the years due to its widespread use and historical vulnerability disclosures. Once a database is exfiltrated, the data is permanent regardless of what the original site does afterward.
Check If Your Data Was Exposed
HEROIC's free breach scanner searches across more than 400 billion compromised records to check whether your email address appeared in the Demon Forums breach or any other known data leak. Run a free scan now and find out whether your credentials are already in circulation.
Breach Breakdown
9,797 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds