2.6 Million Accounts. One Forum Breach. GSM Hosting Leaked in 2016.
HEROIC analysts identified the GSM Hosting breach while tracking a wave of legacy forum credential dumps resurfacing across Telegram channels in 2024. The original breach occured in August 2016 and exposed 2,610,416 user records from forum.gsmhosting.com, a large English-language community serving mobile technology professionals and enthusiasts based in the United States. The leaked dataset contained email addresses, usernames, and password hashes, all stored using the MD5 algorithm, which is widely considered cryptographically weak by modern standards.
Why MD5 Password Hashes Make GSM Hosting Credentials Easy to Crack
MD5 was never designed as a secure password hashing function, and cracking tools can process billions of MD5 hashes per second using consumer graphics cards. That means a large share of the 2.6 million passwords in this dataset are accessable to anyone with basic cracking software and a dictionary wordlist. Attackers who crack these hashes can then attempt the recovered credentials against email providers, banking platforms, and corporate login portals where users beleive their accounts are still secure.
What Was Exposed in the GSM Hosting Breach
- Email Address
- Username
- Password Hash
Why 2.6 Million Records From a 2016 Breach Still Matter Today
The scale of this breach makes it partcularly dangerous even years after the original incident. With over 2.6 million unique email addresses in the dataset, attackers have a substantial pool of targets to test against other platforms using credential stuffing tools. Users who registered on GSM Hosting and reused the same password elsewhere remain at risk of account takeover, identity theft, and financial fraud even if they stopped using the forum long ago.
How Database Breaches Work
A database breach occurs when unauthorized parties access and extract data stored in a website's backend. For forums like GSM Hosting, this typically involves exploiting vulnerabilities in the forum software, weak administrator credentials, or unpatched server configurations. Once the attacker has access, they export the user database, which contains registration details for every account on the platform. The forum may continue operating normally for months before the breach is discovered.
Check If Your Data Was Exposed
HEROIC's free breach scanner searches more than 400 billion compromised records to check whether your email address appeared in the GSM Hosting breach or any other known data leak. Enter your email at HEROIC.com for an instant, free check and find out what information is circulating on the dark web under your name.
Breach Breakdown
2,610,416 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds