Plex
We've been tracking a resurgence of older breaches, often resurfacing in aggregated credential dumps on Telegram channels. What really struck us wasn't the size of these dumps—it was the consistent presence of credentials from services that, while not always critical infrastructure, are deeply embedded in users' personal and professional lives. This pattern suggests attackers are finding value in "legacy" breaches, using them to pivot into more valuable targets through password reuse or to gather intelligence for social engineering attacks.
Plex Forum Breach: 280K Accounts Resurface in Credential Dumps
In July 2015, a breach of the Plex media center's discussion forum compromised over 327k accounts. While the incident itself is not new, the data has been observed circulating in recent credential stuffing lists and on Telegram channels dedicated to trading leaked databases, indicating its continued relevance to attackers. The breach initially targeted the IP.Board forum software used by Plex, exposing a range of user data.
The breach was first reported in July 2015 following user reports of suspicious activity on their Plex accounts. Investigations confirmed that the forum database had been compromised, leading to the exposure of user credentials. What caught our attention was the weak hashing algorithm used to protect passwords at the time. The passwords were stored as salted hashes, but the implementation was insufficient, allowing for many to be easily cracked. This means that even users who changed their passwords *after* the 2015 breach may still be vulnerable if they reused the same passwords elsewhere.
This breach matters to enterprises now because it highlights the long tail of risk associated with older breaches and the continued threat of password reuse. Employees may have used their corporate email addresses when registering for personal services like Plex, making them vulnerable to credential stuffing attacks against corporate systems. The availability of cracked passwords from this breach increases the likelihood of successful account takeovers.
- Total records exposed: 280,185
- Types of data included: Email Addresses, Usernames, Passwords (hashed), IP Addresses
- Hash Type: Salted hashes (weak implementation)
- Source structure: Database dump from IP.Board forum software
- Leak location(s): Telegram channels, credential stuffing lists, online forums
- Date of first appearance: July 2, 2015
Security researcher Troy Hunt added the Plex breach to Have I Been Pwned? shortly after it occurred in 2015. The incident was also widely discussed on security forums at the time, with users sharing techniques for identifying and mitigating compromised accounts.
Breach Breakdown
280,185 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds