Breach Intelligence Report 03 Nov 2025

Inside the Moonsault Breach: How 22,344 Records Were Compromised

HEROIC
HEROIC Threat Intelligence Team
Email Address Password Hash
Your email may be in this breach. Check in 5 seconds — free, no signup required.
Scan Email →
Records Exposed 22,344
Source Type Database,Combolist
Origin Darkweb
Password Type MD5

In August 2018, Moonsault, a popular German-language professional wrestling news and community website, had its user database leaked on a well-known hacking forum. The breach exposed 22,344 registered users, with their email addresses and MD5-hashed passwords now freely available to anyone who knew where to look. For a niche community site, that's a substantial number of real people whose account security was compromised without their knowledge.

Why This Is Dangerous


MD5 is not a secure password hashing algorithm. It was never designed to be one, and the security community has known this for a long time. MD5 hashes can be cracked at enormous speed using modern graphics cards, and vast precomputed tables of common passwords already exist for exactly this purpose. An attacker who downloads this dataset does not face much of a barrier when it comes to recovering the actual passwords.

Once cracked, those passwords become usable on any other service where the victim reused them. Email accounts, social media, online banking, and workplace systems are all fair game if the password matches. Moonsault users who recycled their passwords across multiple sites may have recieved much broader damage from this breach than just losing access to a wrestling forum account.

The combination of email address and a crackable password hash is a classic entry point for credential stuffing campaigns. These attacks are largely automated and can test millions of credential pairs per hour across hundreds of websites, making even a moderately sized breach like this one genuinely dangerous at scale.

What Was Exposed


  • Email addresses
  • MD5 password hashes (highly susceptible to cracking)
  • Usernames or display names
  • Account registration dates
  • User profile preferences or settings
  • Forum post history references or user IDs
  • Language and locale information (German-language platform)

Why This Matters


Twenty-two thousand people joined Moonsault to talk about professional wrestling, not to have their account data end up on a hacking forum. The breach is a reminder that even small community sites carry real security obligations. Users share their email adresses and create passwords that they often reuse elsewhere, and when that data leaks, the consequences extend far beyond the original site.

This kind of data does not go away once it's posted. The Moonsault dump from 2018 has almost certainly been rolled into combolists that are still circulating today. Anyone who had an account and never changed their password since then should beleive that their credentials are likely still in active use somewhere in the credential stuffing ecosystem.

How Database Combolist Works


A combolist breach starts with an attacker gaining unauthorized access to a website's database. In cases like Moonsault, this often happens through SQL injection, server misconfigurations, or exploiting vulnerabilities in forum software like phpBB or vBulletin. Once the attacker has database access, exporting the user table takes only seconds.

The raw dump typically contains hashed passwords. With MD5, an attacker can run the hashes through a cracking tool and recover a significant percentage of passwords within hours, especially common ones. The resulting email-and-password pairs are then packaged into a combolist, formatted in a standard way that automated credential stuffing tools can ingest directly.

These combolists get traded, sold, and merged with other dumps over time. A breach posted to a forum in 2018 might reappear in a larger aggregated dump in 2021, and again in a different form in 2024. The data continues to be useful to attackers as long as even a fraction of the victims still use the same passwords on other services.

Check If You Were Affected


If you had an account on Moonsault or have used the same email and password combination on other platforms, your credentials may still be in active circulation. Check HEROIC's free breach monitoring tool at heroic.com to see if your email appears in known breach datasets and learn what steps to take to protect your accounts.

Breach Breakdown

Domain N/A
Leaked Data Email Address,Password Hash
Password Types MD5
Date Leaked 03 Nov 2025
Check in 5 seconds

22,344 passwords exposed. Is yours one of them?

Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.

All information submitted is Private and Secure. We do not sell or share email addresses. By searching, you agree to HEROIC's Privacy Policy and Terms of Service.

Free forever · No account required · Results in seconds

Private & Secure No Account Needed 2,397 scanned today
Breach Rank #N/A by affected users
Impact Score
1
sensitivity + scale + recency
Est. Financial Impact $161.7K fraud, phishing & misuse risk
Scan your email Free →
Scan to sign up

Scan to sign up instantly

24/7 Dark Web Monitoring
Instant Breach Alerts
Secure Data Protection
Your Data is at Risk

Your Personal Information is Exposed

We found your data exposed in multiple breaches. This includes:

  • Email addresses
  • Passwords
  • Phone numbers
  • Financial information
Secure My Information Now

Your information is protected by enterprise-grade security

Your Breach Details

Date:
Severity:
Records Exposed:

Your Exposed Information

Your Risk Level

How This Affects You

Full Breach Details

Premium Insights

Unlock Critical Security Information

Create a free account to access:

  • Full Breach Impact Analysis
  • Identity Theft Risk Score
  • Exposed Credentials Details
  • Personalized Security Recommendations
Create Free Account

Identity Theft Risk Score

Risk Score: 8.7/10 - Critical

Data Exposure Analysis

Passwords Critical
Financial High
Personal Medium
Social High
Security Critical

Breach Timeline Analysis

March 2024 Multiple credentials exposed in recent data breach
January 2024 Password found in dark web marketplace
December 2023 Personal information leaked in major security incident

Security Recommendations

High Priority
Password Security

Critical: Change compromised passwords immediately and enable 2FA on all accounts

Important
Financial Protection

Monitor credit reports and set up fraud alerts with major credit bureaus

Recommended
Identity Protection

Enable advanced identity monitoring and dark web surveillance