Identity Theft Just Got Easier: The ForumCommunity Breach Left 754K Passwords Exposed
HEROIC analysts identified the ForumCommunity breach as part of ongoing monitoring of credential datasets circulating across dark web forums and breach aggregation platforms. The breach occured in June 2016, when a database belonging to ForumCommunity, an Italian platform used for creating online forums, was compromised. Over 754,294 user records were exposed, containing email addresses and plaintext passwords. The fact that these credentials were stored without any encryption is partcularly alarming, as it meant attackers had immediate, ready-to-use access to every account in the dataset.
What Attackers Can Do With Plaintext Passwords
Unlike hashed passwords, plaintext credentials require zero effort to use. Anyone who recieved this dataset could immediately log into ForumCommunity accounts and then attempt those exact same username and password combinations across hundreds of other websites. Email providers, banking apps, and workplace tools are common targets. Because so many people reuse passwords, a single old breach like this can unlock dozens of accounts belonging to the same person.
What Was Exposed in the ForumCommunity Breach
- Email Address
- Plaintext Password
Why This Breach Is Still a Threat in 2024
Old breaches do not expire. The ForumCommunity data has continued to circulate and get bundled into new aggregated leak packages years after the original incident. Anyone who used the same email and password on ForumCommunity and any other platform remains at risk today. Credential stuffing attacks, where bots automatically test leaked logins across thousands of sites, are beleived to account for billions of failed login attempts every year. If you have not changed your password since 2016, your account on other platforms may already be compromised.
How a Database Breach Works
A database breach happens when an attacker gains unauthorized access to a website or application's backend storage, where user information is kept. This can happen through a software vulnerability, a misconfigured server, or stolen admin credentials. Once inside, the attacker copies the database and takes it offline for later use. In cases like ForumCommunity, where passwords were stored in plaintext rather than encrypted form, the stolen data is instantly usable with no additional work required by the attacker.
Check If Your Data Was Exposed
HEROIC offers a free breach scanner backed by a database of over 400 billion compromised records. You can check in seconds whether your email address or passwords appeared in the ForumCommunity breach or any of thousands of other known incidents. Visit HEROIC's breach scanner to find out if your data is at risk and get steps to protect yourself today.
Breach Breakdown
754,294 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds