The MSPA Forums Breach Put 180,784 Login Credentials Online
HEROIC analysts identified a database breach connected to MSPA Forums, an online discussion community built around the webcomic Homestuck at mspaforums.com. The breach dates to March 1, 2016, and exposed 180,784 records. The exposed data included email addresses, usernames, IP addresses, password hashes, and the salt values used to protect those passwords. Passwords were hashed using vBulletin's built-in method.
Why the MSPA Forums Breach Is Dangerous
Having the salt values exposed alongside the password hashes removes one of the main protections salting is supposed to provide. Normally, salts make it harder for attackers to crack many passwords at once using pre-computed tables, but when the salt is stolen right along with the hash, an attacker can still crack each password individually with enough computing time. Combined with email addresses, usernames, and IP addresses, this gives an attacker nearly everything needed to impersonate an affected member or target them directly.
What Was Exposed in the MSPA Forums Leak
- 180,784 total records from the mspaforums.com community
- Email addresses
- Usernames
- IP addresses
- Password hashes and their associated salts, hashed with vBulletin's method
Why This Matters
A forum built around a shared hobby might feel low risk, but the combination of data exposed here is exactly what attackers need for credential stuffing. Once a password is cracked, an attacker pairs it with the matching email address and tries it against other popular sites, betting that the person reused the same login somewhere more valuable. The IP addresses in this leak add another layer of risk, potentially helping an attacker narrow down a target's general location for more convincing phishing attempts.
How a Database Breach Like This Happens
A database breach happens when an attacker finds a way into a website's backend, often through a vulnerability in the forum software itself, and copies the user table directly. vBulletin, the forum software MSPA Forums ran, has a long history of security issues in older versions, which made this kind of direct database theft possible in 2016 and remains a risk for any site still running unpatched forum software today.
Check If You're Affected
If you've ever had an account on MSPA Forums, or you tend to reuse passwords across hobby and community sites, it's worth checking your exposure. HEROIC's free breach scanner checks your email against a database of more than 400 billion leaked records in seconds.
Breach Breakdown
180,784 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds