Breach Intelligence Report 25 Jul 2022

Breached in 2016, the NWGT.org Database Dump Is Still Trading Today

HEROIC
HEROIC Threat Intelligence Team
None
Your email may be in this breach. Check in 5 seconds — free, no signup required.
Scan Email →
Records Exposed 553
Source Type Database
Origin Darkweb
Password Type vB

HEROIC analysts flagged the NWGT.org database during a timeline review of breach datasets originating from November 2016, a period when several vBulletin-powered community forums were systematically targeted. The breach captured 553 registered user records from nwgt.org, a forum categorized under drug-related harm reduction and discussion communities. The data was recieved as part of an older aggregated collection that has resurfaced in active trading channels, meaning credentials from this breach are once again in circulation nearly a decade after the original incident occured. The timing of resurfacing matters as much as the original breach date.


Why Harm Reduction Forum Credentials Carry Elevated Privacy Risk

A breach from a forum in a sensitive category like this one carries risks that go beyond typical credential stuffing. The email addresses and usernames exposed here are seperate from the password data but remain valuable on their own. Attackers can use membership in sensitive communities as leverage for targeted phishing, blackmail attempts, or social engineering. When someone's participation in a sensitive forum is made accessable through a breach dataset, the privacy harm extends well beyond whether the password still works on another platform.


What Was Exposed in the NWGT.org Breach

  • Usernames
  • Email addresses
  • Passwords (vBulletin hashed format)
  • Account registration data

Breached in 2016, Still in Circulation: Why the Timing Matters

Most people assume that a breach from years ago has already been dealt with. The reality is partcularly different. Older breach datasets often cycle back into active trading when they get incorporated into new combo lists or shared on fresh forums. The NWGT.org data resurfacing now means it is being used in credential stuffing attacks today, not in 2016. Users who registered on this forum and reused those credentials on email, banking, or social media accounts face real account takeover risk. Identity theft and financial fraud follow directly from these automated attacks when they succeed.


How a Database Breach Works

A database breach occurs when an attacker gains unauthorized access to the server storing a website's user data. For forum platforms using vBulletin software, attackers often exploit known vulnerabilities in older, unpatched versions of the software to extract the database. Once they have the file, they can crack the hashed passwords using modern tools and then use the resulting plaintext credentials to attempt logins across other platforms. This entire process can happen quickly and silently, with users having no awareness that their data has been taken.


Check If Your Data Was Exposed

HEROIC's free breach scanner searches more than 400 billion exposed records, including datasets like NWGT.org that predate public awareness but remain active in the threat landscape. Enter your email address now at HEROIC to see exactly which breaches include your data. The sooner you know, the sooner you can take action to protect your accounts and your privacy.

Breach Breakdown

Domain N/A
Leaked Data None
Password Types vB
Date Leaked 25 Jul 2022
Check in 5 seconds

553 passwords exposed. Is yours one of them?

Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.

All information submitted is Private and Secure. We do not sell or share email addresses. By searching, you agree to HEROIC's Privacy Policy and Terms of Service.

Free forever · No account required · Results in seconds

Private & Secure No Account Needed 2,397 scanned today
Breach Rank #N/A by affected users
Impact Score
0
sensitivity + scale + recency
Est. Financial Impact $4.0K fraud, phishing & misuse risk
Scan your email Free →
Scan to sign up

Scan to sign up instantly

24/7 Dark Web Monitoring
Instant Breach Alerts
Secure Data Protection
Your Data is at Risk

Your Personal Information is Exposed

We found your data exposed in multiple breaches. This includes:

  • Email addresses
  • Passwords
  • Phone numbers
  • Financial information
Secure My Information Now

Your information is protected by enterprise-grade security

Your Breach Details

Date:
Severity:
Records Exposed:

Your Exposed Information

Your Risk Level

How This Affects You

Full Breach Details

Premium Insights

Unlock Critical Security Information

Create a free account to access:

  • Full Breach Impact Analysis
  • Identity Theft Risk Score
  • Exposed Credentials Details
  • Personalized Security Recommendations
Create Free Account

Identity Theft Risk Score

Risk Score: 8.7/10 - Critical

Data Exposure Analysis

Passwords Critical
Financial High
Personal Medium
Social High
Security Critical

Breach Timeline Analysis

March 2024 Multiple credentials exposed in recent data breach
January 2024 Password found in dark web marketplace
December 2023 Personal information leaked in major security incident

Security Recommendations

High Priority
Password Security

Critical: Change compromised passwords immediately and enable 2FA on all accounts

Important
Financial Protection

Monitor credit reports and set up fraud alerts with major credit bureaus

Recommended
Identity Protection

Enable advanced identity monitoring and dark web surveillance