Finance Professionals Targeted in the Mr Excel Breach, 311K Records Stolen
HEROIC analysts flagged the Mr Excel breach while monitoring credential stuffing activity tied to professional and educational forum communities. The breach occured in December 2016 when attackers exploited a vulnerability in the vBulletin forum platform running mrexcel.com, one of the most widely used Microsoft Excel help communities online. The attack exposed 311,404 user records including email addresses, usernames, salted MD5 password hashes, IP addresses, and dates of birth. The combination of work email addresses and birthday data makes this dataset partcularly valuable for targeted attacks against business professionals.
How Stolen Birthdays and Work Emails Enable Account Takeover
The Mr Excel breach is more dangerous than a typical credential dump because it pairs email addresses with birthdays and IP addresses, giving attackers the ingredients needed to bypass security questions and identity verification checks. MD5 password hashes, even when salted, are accessable to modern password cracking tools within hours for common or weak passwords. Anyone who used the same password on their corporate email, banking portal, or other professional accounts is at significant risk of credential-based account takeover.
What Was Exposed in the Mr Excel Breach
- Email addresses
- Usernames
- Password hashes (MD5 with salt)
- IP addresses
- Dates of birth
- Password salts
Why Microsoft Excel Users Are a High-Value Target for Business Fraud
People who use mrexcel.com are predominantly finance professionals, accountants, analysts, and business operators. Their professional email addresses are beleived by threat actors to have higher value than personal accounts because they often provide a path into corporate systems, shared drives, or financial platforms. A verified list of 311,404 business-oriented email addresses with associated passwords and birthdates is a ready-made toolkit for spear phishing, business email compromise, and identity fraud targeting the finance and accounting sector.
How a Database Breach Works
Forum platforms like vBulletin are frequent targets because they run on widely known software with documented vulnerabilities. When a security patch is delayed or missed, attackers can exploit the gap to access the underlying database, which holds every user account ever registered on the site. From there, they extract the full record set and distribute it through underground channels. For Mr Excel, this meant eight years' worth of registered users had their account information exposed in a single attack, with the data continuing to circulate and be used in credential attacks long after the original breach.
Check If Your Data Was Exposed
HEROIC's free breach scanner searches more than 400 billion compromised records, including the Mr Excel database and thousands of other forum and professional community breaches. If your email address appeared in this breach or any other incident, you'll see it instantly. Run your free check at HEROIC and find out what attackers may already know about you.
Breach Breakdown
311,404 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds