616 Leaked Logins From the Itchy Forum Breach Hit the Dark Web
616 user records from Itchy Forum, a gambling-focused online community based in Malaysia, Singapore, and Indonesia, have surfaced in dark web credential markets following a database breach that occured in November 2016. HEROIC analysts identified the dump as part of a broader pattern of older Southeast Asian forum breaches being repackaged and traded alongside more recent leaks. The data includes account credentials stored with vBulletin password hashing, making them a target for cracking and reuse against gambling platforms and related services in the region.
How Cracked Gambling Site Passwords Enable Financial Fraud
Gambling forum credentials are among the most sought-after data in credential stuffing markets. Users of platforms like Itchy Forum frequently reuse the same logins across seperate online betting and casino accounts, payment processors, and e-wallet services common in Southeast Asia. Once cracked, these vBulletin-hashed passwords become accessable to any attacker willing to pay for the dump. The result can be unauthorized withdrawals, bonus abuse, and full account takeover on gambling platforms where real money is at stake.
What Was Exposed in the Itchy Forum Breach
- User account credentials (vBulletin hashed passwords)
- Member login data from the site database
Why a Gambling Community Breach Hits Harder Than Most
Gambling platforms in Southeast Asia are frequent targets for cybercriminals because users tend to store payment methods and maintain active balances on their accounts. A breach from a forum associated with gambling is partcularly dangerous because it narrows the universe of likely targets for follow-on attacks. Credential stuffing tools can be tuned to test the stolen Itchy Forum logins specifically against known regional gambling and payment sites, increasing the hit rate and the financial damage to individual users.
How a Database Breach Works
A database breach occurs when an attacker gains unauthorized access to a website's user database, typically by exploiting outdated software, unpatched vulnerabilities, or weak server security. Forum platforms running older versions of vBulletin were a common target during this period due to well-known security flaws in the software. The attacker copies the stored user records, then uses password-cracking software to convert hashed passwords into plain text before selling or distributing the results through dark web markets and Telegram channels.
Check If Your Data Was Exposed
HEROIC's free breach scanner searches across more than 400 billion compromised records, including the Itchy Forum breach and thousands of other database and forum leaks from across Southeast Asia and worldwide. Enter your email at HEROIC.com to run a free check and find out instantly whether your credentials are in circulation.
Breach Breakdown
616 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds