Our Analysts Found the International Skeptics Dump in a vBulletin Breach Batch
HEROIC analysts uncovered the International Skeptics database while tracing a batch of vBulletin forum dumps that circulated through private sharing channels in late 2023. The breach originally occured in November 2016 and captured 383 user records from internationalskeptics.com, a longstanding online forum for evidence-based critical discussion. The dataset was recieved as part of a larger collection of smaller forum breaches being traded together, suggesting coordinated harvesting of vBulletin-powered communities around the same period. The age of the breach does not reduce the risk. It increases it, because affected users have had years to reuse those credentials elsewhere.
Why Forum Account Credentials Enable Phishing and Account Takeover
Even without a password field in the dump, usernames and email addresses from a breach like this are accessable to anyone who trades in stolen data. Attackers use this information to craft convincing phishing emails that appear to come from platforms the target actually uses. Combined with cracked vB password hashes, these credentials are also tested against email providers, social media accounts, and any other platform where the same login combination might work. The risk is not hypothetical. It is the standard playbook for credential-based attacks.
What Was Exposed in the International Skeptics Breach
- Usernames
- Email addresses
- Passwords (vBulletin hashed format)
- Account registration metadata
Why Old Forum Breaches Are Still Dangerous in 2024
It is partcularly common for people to dismiss breaches that are years old or involve small communities. But this is exactly what makes them valuable to attackers. Older credentials are less likely to have been changed. Smaller forums are less likely to have notified users. When a dataset like International Skeptics surfaces on trading channels, it gets merged into larger combo lists used for automated credential stuffing. The downstream results include account takeover, identity theft, and in some cases financial fraud when attackers reach linked payment methods through a compromised email account.
How a Database Breach Works
A database breach happens when an attacker finds a way into a website's underlying data storage, usually by exploiting outdated software or a misconfigured server. Forum platforms like vBulletin were popular targets in the mid-2010s because many sites ran old, unpatched versions with publicly known vulnerabilities. Once inside, the attacker copies out the user table and walks away with every registered account in the database. That data then gets sold, traded, or published, sometimes years after the original intrusion.
Check If Your Data Was Exposed
HEROIC's free breach scanner indexes more than 400 billion records from breaches like International Skeptics and thousands of other compromised databases. Enter your email address to find out instantly whether your data has been exposed and where. Take two minutes now to check, before an attacker uses that information to access something far more important than an old forum account.
Breach Breakdown
383 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds