The VBulletin Breach Put 17,373 Users’ Passwords and Data at Risk
HEROIC analysts flagged a database breach tied to vBulletin, the forum software company, dated November 3, 2015. This incident affected 17,373 accounts, exposing email addresses, birth dates, security questions and answers, and passwords protected with vBulletin's salted hashing.
Why the VBulletin Breach Is Dangerous
Security questions and answers are especially risky when they leak, because many people reuse the same answers across banking sites, email providers, and password recovery flows. Combined with a birth date and email address, an attacker has enough to attempt account recovery on other services, even without cracking the password hash itself.
What Was Exposed in the VBulletin Leak
- Email addresses
- Birth dates
- Security questions and answers
- Passwords, protected with salted hashing
Why This Matters
This breach illustrates how identity theft does not always require a cracked password. Birth dates and security question answers are commonly used to verify identity when resetting a password or opening a new account, so this combination of data can support fraud even if the password hash itself holds up.
How Database Breaches Like This Happen
A database breach means an attacker accessed the backend system storing user accounts directly and pulled records in bulk. Because vBulletin powers forums across many industries, an incident affecting the company itself can expose account recovery information tied to communities well beyond a single website.
Check If You Are Affected
If you have ever had a forum account built on vBulletin, check whether your information is part of this leak. HEROIC's free breach scanner checks your email against more than 400 billion compromised records, including this one, in seconds.
Breach Breakdown
17,373 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds