SixManFootball Data Breach: 15,582 Forum Accounts Exposed (2018)
Small-Town American Football, Global Credential Theft
Six-man football is about as niche as American sports get -- a small-school variant played mostly in rural Texas and a handful of other states where districts can't field an eleven-man team. The SixManFootball.com forum served that community for years as a hub for coaches, fans, and players. When its database surfaced on underground sources in August 2018 with 15,582 user records, it demonstrated something important: attackers don't discriminate by audience size. Niche community credentails are still credentials, and every exposed email-password pair is futher ammunition for automated stuffing campaigns hitting everything from Gmail to enterprise SSO portals.
SixManFootball (August 2018): Breach Summary
- Records Exposed: 15,582
- Data Types: Email addresses, pHpass password hashes
- Breach Type: Database dump / Combolist
- Country Affected: United States
- Date Leaked: August 26, 2018
pHpass: Weaker Than It Looks
The SixManFootball database used pHpass (Portable PHP Password Hashing Framework) -- a hashing scheme specifially designed for older PHP applications including early WordPress and phpBB installations. While pHpass added salting to improve on raw MD5, it's been consistently criticized for its low iteration count and susceptibility to GPU-accelerated brute force. Tools like Hashcat support pHpass cracking natively, and with a wordlist of common passwords, a significant percentage of these hashes can be recovered on consumer hardware within days. The 15,582 hashed passwords aren't safe by default -- they represent a cracking challenge that any moderately equipped attacker can realistically complete.
Forum Databases and Credential Reuse Chains
Sports forums from the mid-2000s to early 2010s era share a common vulnerability: they were typically small operations run by enthusiasts, not security professionals. Registration was casual -- many users signed up with the same email and password they used everywhere else, including work email addresses. When those accounts appear in a combolist years later, the value isn't the forum account itself (which likely no longer exists) -- it's the associated email address and reused password that opens doors to other systems. This is the mechanism through which small, obscure forum breaches produce outsized damage in credential stuffing ecosystems long after the original site has gone quiet.
Part of the August 26, 2018 Mass Release
SixManFootball was among more than ten platforms whose databases were released on August 26, 2018 in a coordinated or near-simultaneous dump spanning the United States, Germany, Thailand, Italy, Ireland, Japan, Nepal, Poland, and the Netherlands. The single-day release of this many databases across so many countries points to a batch operation -- a threat actor or group clearing out an inventory of previously hoarded breach data. Each individual database looks small in isolation; aggregated, the August 26 cluster represents a significant credential injection into underground marketplaces that combolist compilers drew from for months afterward.
Check If Your Credentials Were Exposed
HEROIC's free breach scanner searches across more than 400 billion exposed records -- including forum databases like SixManFootball. Even if you haven't thought about this platform in years, your registration email and password may still be circulating in active credential stuffing lists. A quick scan takes seconds and can flag your exposure before it becomes an account takeover incident on a platform that actually matters.
Breach Breakdown
15,582 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds