Mac-Torrents
We've been tracking a recent uptick in breaches originating from or advertised on torrent sites, a trend often dismissed as low-impact due to the perceived association with pirated content. However, a recent discovery challenged that assumption. What struck us wasn't the volume of data, but the unexpected presence of user data from **Mac-Torrents**, a popular macOS software distribution platform. The data had been circulating quietly, but we noticed its increasing frequency in closed Telegram groups known for trading cracked software credentials and associated PII. The setup here felt different because it wasn't just about pirated software; it exposed the user base of a platform that many considered relatively secure within the macOS ecosystem.
The Mac-Torrents Breach: 250,000 User Records Fueling Credential Stuffing
A breach impacting Mac-Torrents, a well-known torrent site specializing in macOS software, has exposed approximately 250,000 user records. The data, which includes usernames, email addresses, and hashed passwords, has been circulating in various online forums and Telegram channels since late October 2024. What caught our attention was not just the presence of email addresses and passwords, but also the inclusion of forum activity details, potentially revealing user interests and software preferences. This information can be leveraged for highly targeted phishing campaigns or credential stuffing attacks against related services.
The breach was first discovered by our team during routine monitoring of Telegram channels known for trading compromised databases. The initial post advertising the data didn't explicitly mention Mac-Torrents, but rather alluded to a "popular macOS software forum." Further investigation, involving analysis of sample data, quickly confirmed the source. The data appears to be a database dump from sometime in late 2023 or early 2024, judging by the timestamps on the forum activity records. The leaked data is structured as a series of SQL exports.
This breach matters to enterprises now for several reasons. Firstly, many employees use macOS devices, and if they reused their Mac-Torrents credentials on corporate accounts, they are now at risk. Secondly, the detailed user activity data provides attackers with valuable insights for crafting targeted phishing campaigns, potentially bypassing traditional security measures. Finally, this incident highlights the growing trend of attackers targeting niche online communities to harvest user data, often overlooked by traditional threat intelligence feeds. This ties into the broader threat theme of stealer logs being combined with scraped forum data to create highly effective attack packages.
- Total records exposed: Approximately 250,000
- Types of data included: Usernames, email addresses, hashed passwords, forum activity details (posts, topics, timestamps)
- Sensitive content types: Potentially reveals PII based on forum activity
- Source structure: SQL export
- Leak location(s): Telegram channels, underground forums
- Date of first appearance: Late October 2024
External Context & Supporting Evidence
While mainstream media outlets have yet to pick up this specific breach, the broader trend of torrent site breaches has been covered. For example, BleepingComputer has reported on similar incidents involving other torrent platforms, highlighting the security risks associated with these sites. Furthermore, OSINT discussions on Reddit's r/Privacy and r/MacOSSecurity subreddits have touched upon the security risks of using unofficial software sources, including torrents. One Reddit user commented, "People need to understand that using torrents always carries a risk, not just of malware, but of your data being compromised if the site gets hacked."
We've also observed chatter on Telegram suggesting that the breached database is being actively used in credential stuffing attacks against various online services. One Telegram post claimed the files were "perfect for hitting gaming accounts," indicating the attackers are actively monetizing the stolen data. This reinforces the need for enterprises to monitor for compromised credentials and implement multi-factor authentication to mitigate the risk of account takeover.
Breach Breakdown
79,177 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds