Data breach
Cracking Forum
- Records
- 469,424
- Breach date
- 1 January 2015Estimated
- Added
- 1 December 2024
What was exposed
2 types of data · 1 puts you at serious risk
- Email addresses469,424
- Passwords469,321
About this breach
A forum built around breaking passwords appears to have had its own users' credentials exposed. The investigation team has indexed a listing tied to Cracking Forum, a crackingforum.com community whose members traded tools and techniques for defeating software protection and account security. The team estimates the underlying breach occurred around January 2015, and the listing contains 469,424 rows of email addresses paired with passwords. No individual or group has claimed responsibility for the breach, and the team has not confirmed how the data was obtained. Public reporting on this specific incident is also sparse, so much of what follows rests on the indexed fields themselves.
Limited public reporting: As of September 25, 2026, detailed company notices or major news coverage for this listing were limited in sources reviewed. The facts below rely primarily on the indexed fields plus any secondary sources cited.
One note on dating: independent sources describe more than one incident involving this forum, at dates that do not match this listing. Mozilla Monitor records a CrackingForum breach on July 1, 2016, and HEROIC ties an exposure of more than 560,000 accounts to December 2014. LeakCheck also lists a CrackingForum.com entry with a November 2014 breach date. Whether the January 2015 listing in the index is a separate incident or a differently dated copy of material from one of those events has not been confirmed. Readers should treat the estimated date accordingly.
What Information Was Compromised?
Our analysis found the following data types in this breach:
Email addresses: 469,424
Passwords: 469,321
Every row in the listing includes an email address, and nearly all rows include a password. That combination, at this scale, is a classic credential dump: a direct line from an account name to the secret that protects it. The listing does not include usernames, IP addresses, or other profile details, according to the investigation team's fields.
Not every individual is affected by every type of data listed here.
What Are the Potential Risks for Affected Individuals?
The main danger from a breach like this is reuse. Many people use the same password across multiple services, and attackers know it. A password exposed on a forum in 2015 can still open doors today if it was never changed elsewhere.
Concrete risks include:
Credential stuffing: Attackers feed exposed email and password pairs into login pages for email providers, banks, shopping sites, and social networks, betting that some passwords work elsewhere.
Account takeover: Any account that still uses an exposed password is a realistic target, especially for email accounts that can be used to reset other passwords.
Phishing: A known email address tied to a cracking community makes a person an easier target for convincing scam messages, since attackers can tailor the story to the victim's interests.
What Should You Do If You Were Affected?
If your email address appears in this listing, take these steps:
Change the exposed password everywhere it was used. Start with your email account, then banking and any account holding payment details.
Use a unique password for each important account. A password manager makes this manageable.
Turn on two-factor authentication wherever it is offered, especially for email, which controls password resets for everything else.
Watch for phishing. Attackers who hold your email address may send messages pretending to be from services you use. Do not click links in unexpected security alerts; go to the site directly instead.
Because Cracking Forum's data was circulated without a verified claim by any attacker, there is no official notice or remediation program to point to. The steps above are the practical defense available.
