The Nihonomaru Anime Forum Breach Hit 1.4 Million US Accounts
HEROIC analysts identified a breach connected to Nihonomaru, a US-registered anime community forum at nihonomaru.net, that exposed 1,447,708 user records. The breach dates back to December 1, 2015, and the exposed data set includes IP addresses, email addresses, usernames, and passwords hashed using the vBulletin forum software's hashing method.
Why the Nihonomaru Breach Still Puts 1.4 Million People at Risk
vBulletin's password hashing, while salted, is an older method that can be cracked with modern hardware, especially at the scale of this breach. Once cracked, those passwords are tied directly to email addresses, usernames, and IP addresses, giving attackers everything needed to break into other accounts, track down a user's general location, or build convincing phishing messages aimed at former Nihonomaru members.
What Was Exposed in the Nihonomaru Breach
- IP addresses
- Email addresses
- Usernames
- Passwords (vBulletin hashed)
Why This Matters for Former Nihonomaru Members
At nearly 1.5 million accounts, this breach is large enough to be a meaningful source of credentials for automated credential stuffing attacks, where attackers test stolen email and password pairs against banking sites, email providers, and gaming or social platforms. Anime and fandom communities often share overlapping membership with gaming accounts, so a reused password from Nihonomaru could put a much more valuable account at risk today, a decade after the original breach.
How a vBulletin Forum Breach Happens
Nihonomaru ran on vBulletin, a widely used forum platform that has been the target of numerous exploits over the years. Attackers typically gain access by exploiting a known software vulnerability or an unpatched plugin, then export the entire user database, including hashed passwords, salts, emails, usernames, and IP logs. That stolen database is then packaged and distributed on hacking forums and messaging channels, where it can continue circulating and resurfacing for years after the original theft.
Check If You Are Affected
With more than 1.4 million records exposed, this breach represents a large pool of credentials that could still be actively used in attacks. HEROIC's free breach scanner checks your email address against a database of more than 400 billion leaked records, including this one, so you can find out in seconds whether your information was exposed and take action to secure your accounts.
Breach Breakdown
1,447,708 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds