How the ForceOnline Breach Exposed 831,000 Plaintext Passwords
HEROIC analysts flagged the ForceOnline breach after noticing renewed activity around this dataset on underground forums in early 2025. The original incident took place in February 2018, when attackers gained access to the ForceOnline database and extracted over 831,000 user records. Each record contained an email address paired with a plaintext password, meaning the site had been storing user passwords with no encryption or protection whatsoever. For a platform serving nearly a million users, this failure to follow basic security standards left everyone exposed in the worst possible way. Our team beleives the data has continued to circulate quietly since 2018, with fresh interest now pushing it back into active use.
What Attackers Can Do With 831,000 Email and Password Pairs
Plaintext passwords are the most dangerous kind of stolen credential because they require zero additional work to exploit. Attackers can load the entire ForceOnline database into automated tools that test each email and password pair against dozens of popular websites simultaneously. Banking portals, email providers, and shopping accounts are all fair targets. Because most people reuse passwords, a single breach from a long-forgotten site can become the key that unlocks accounts the victim actually cares about. The fact that these passwords were not hashed or encrypted means anyone who ever downloaded this dataset has been able to use it as-is from day one.
What Was Exposed in the ForceOnline Breach
- Email Address
- Plaintext Password
Why a Breach From a Defunct Site Is Still a Real Threat Today
Many people assume that when a website shuts down, any data it held disappears with it. That is not how data breaches work. Once a database is copied and shared online, it circulates indefinitely through underground markets and private Telegram groups. The ForceOnline credentials are still being tested against active accounts through credential stuffing attacks, which are entirely automated and cost attackers almost nothing to run. Account takeover, identity theft, and financial fraud remain seperate but connected risks for anyone whose email and password appeared in this breach, especially if those credentials were reused on other platforms.
How a Database Breach Works
A database breach happens when an attacker finds and exploits a security weakness to gain unauthorized access to a website's backend data storage. This can happen through unpatched software vulnerabilities, exposed administrative login pages, or misconfigured server settings. Once access is gained, the attacker can copy the entire user database in a matter of minutes. When passwords are stored in plaintext rather than using a secure one-way hashing algorithm, the stolen file is immediately usable with no further steps needed. The data is then sold or distributed on dark web forums and Telegram channels, where it can remain accessible for years.
Check If Your Data Was Exposed
HEROIC offers a free breach scanner that checks your email against more than 400 billion records from known data breaches, including ForceOnline. Run a free scan now to find out whether your credentials are circulating and get clear guidance on what steps to take to protect your accounts right away.
Breach Breakdown
831,101 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds