Data breach
Avast
- Records
- 422,870
- Breach date
- 26 May 2014Estimated
- Added
- 1 December 2024
What was exposed
3 types of data · 1 puts you at serious risk
- Email addresses422,870
- Usernames422,866
- Passwords65,539
About this breach
In late May 2014, attackers broke into the community support forum run by Avast, the Prague-based antivirus company. The forum, built on Simple Machines Forum software, was taken offline after the company detected the intrusion. According to Avast CEO Vince Steckler, the attack compromised user nicknames, usernames, email addresses, and hashed passwords. Steckler said no payment, license, or financial systems were accessed, and that fewer than 0.2 percent of Avast's roughly 200 million users were affected. Our investigation team estimates the breach affected 422,870 accounts, with an estimated attack date of May 26, 2014. The listing was added to our database on December 1, 2024. No claiming actor has been identified.
May 26, 2014: Avast CEO Vince Steckler published a blog post confirming the community forum had been hacked over the weekend and pulled offline. He wrote that the company detected the attack "essentially immediately" but did not yet know how the attacker breached the forum.
May 27, 2014: Security researcher Graham Cluley reported that approximately 400,000 users were affected and noted the forum ran on Simple Machines Forum software, raising the possibility that it had not been kept up to date with security patches.
What Information Was Compromised?
Our analysis found the following data types in this breach:
Nicknames, present for 422,866 records
Email addresses, present for 422,870 records
Passwords, present for 65,539 records
The passwords in the Avast forum database were hashed, meaning they were stored in one-way encrypted form rather than as plain text. In his blog post, Steckler acknowledged that a sophisticated attacker could still derive many of the passwords from the hashes.
Not every individual is affected by every type of data listed here.
What Are the Potential Risks for Affected Individuals?
Email addresses and usernames can be used for targeted phishing, where attackers send convincing messages that appear to come from Avast or another trusted service. Even hashed passwords carry risk, because attackers can run the hashes through cracking tools, especially where users chose common or weak passwords.
The bigger danger comes from password reuse. Anyone who used the same password on the Avast forum and other websites may find those other accounts accessible to an attacker with the leaked credentials. Because this breach is more than a decade old, exposed email addresses have likely circulated widely and may feed ongoing spam and scam campaigns.
What Is Avast Doing in Response?
Avast responded quickly in 2014. The company took the forum offline, announced the breach in a blog post by CEO Vince Steckler, and emailed users who might be affected. It said all users would be required to set new passwords when the forum returned, because the compromised passwords would no longer work. Avast also said it was rebuilding the forum and moving it to a different software platform, and described the incident as isolated to the third-party community support system. As of September 25, 2026, we have not found more recent public statements from the company specifically about this breach.
What Should You Do If You Were Affected?
Change your Avast forum password if you have not done so since 2014, and change it anywhere else the same password was used.
Turn on two-factor authentication wherever the services you use offer it.
Watch for phishing emails that reference Avast, antivirus software, or account security, and avoid clicking links in unexpected messages.
Use a password manager to create unique passwords for each account, so one breach does not expose others.
In the news
- Graham Cluley, "Avast anti-virus forum hacked, 400,000 users affected" (May 27, 2014)grahamcluley.com (opens in a new tab)
- Nextgov/FCW, "Hackers expose IDs of 400,000 people using security firm Avast's support forum" (May 27, 2014)nextgov.com (opens in a new tab)
- Avast CEO blog post by Vince Steckler (May 26, 2014)blog.avast.com (opens in a new tab)
