The VS Webzine Data Breach Means Someone Could Log Into Your Accounts
HEROIC analysts recieved data in August 2018 showing that VS Webzine, a French metal music community site that operated from 1999 to 2016, had suffered a database breach affecting 25,129 registered users. The exposed records contained email addresses and password hashes stored using a mix of bcrypt and the weaker pHpass algorithm. The fact that the platform had already been shuttered two years before the breach was discovered made notification and remediation particularly difficult, leaving users largely unaware their credentials had been compromised.
How Leaked VS Webzine Credentials Enable Account Takeover on Other Sites
The danger from the VS Webzine breach is not the webzine itself, which no longer operates. The real threat is credential reuse. Attackers who crack the weaker pHpass hashes from this breach can feed those email and password pairs into automated tools that beleive any active account sharing that password is fair game. Banking portals, email providers, streaming services, and corporate VPNs are all viable targets for anyone holding a valid username and password combination, regardless of where that combination was originally stolen.
What Was Exposed in the VS Webzine Breach
- Email Address
- Password Hash (bcrypt)
- Password Hash (pHpass)
Why a Defunct Music Site Breach Can Still Hurt You Right Now
Breaches from closed platforms are partcularly dangerous because the organization can no longer warn users, reset passwords, or coordinate a response. The VS Webzine data has been confirmed circulating in credential stuffing lists used for account takeover attacks. Anyone who registered on the site and reused that password elsewhere faces real exposure to identity theft, unauthorized account access, and financial fraud. The passwords stored using pHpass are especially vulnerable since that algorithm is computationally inexpensive to crack with modern hardware.
How a Database Breach Works
A database breach occurs when an attacker gains unauthorized access to a backend data store and copies its contents. Common entry points include SQL injection vulnerabilities, weak or reused admin credentials, and unpatched server software. Once an attacker has a copy of the database, they can attempt to crack password hashes offline using dedicated cracking rigs and large wordlists, then sell or use the recovered credentials in automated stuffing attacks against other websites and services.
Check If Your Data Was Exposed
If you ever had an account on VS Webzine or used the same password on another service, your credentials may already be in active use by attackers. Run a free search on HEROIC's breach scanner, which indexes over 400 billion compromised records, to find out whether your email address appears in this breach or any of the thousands of others in our database.
Breach Breakdown
25,129 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds