Data breach
CrackingForum
- Records
- 469,451
- Breach date
- 1 July 2016Estimated
- Added
- 29 January 2025
What was exposed
2 types of data · 2 more reported · 1 puts you at serious risk
- Email addresses469,451
- Passwords469,343
- IP addressesReported, not counted
- UsernamesReported, not counted
Reported in the breach write-up; not counted in the analysed data.
About this breach
CrackingForum, an online community dedicated to sharing cracked software and password tools, itself suffered a data breach in mid-2016. According to our investigation team, the breach exposed roughly 469,000 user records, including nearly every user's email address and password. The forum ran on vBulletin software, and secondary breach trackers report that the leaked data included usernames, IP addresses, and salted MD5 password hashes. The incident is a familiar irony in cybersecurity: a forum built around breaking passwords lost its own users' credentials to attackers.
Limited public reporting: As of September 25, 2026, detailed company notices or major news coverage for this listing were limited in sources reviewed. The facts below rely primarily on the indexed fields plus any secondary sources cited.
What Information Was Compromised?
Our analysis found the following data types in this breach:
Email addresses, present in all 469,451 records in our team's index
Passwords, present in 469,343 records
Secondary sources add further detail. Mozilla Monitor lists passwords, IP addresses, email addresses, and usernames as the compromised data types, and reports that the forum ran on vBulletin. North IT describes the exposed passwords as salted MD5 hashes, a hashing method that modern password-cracking tools can defeat comparatively easily.
Not every individual is affected by every type of data listed here.
What Are the Potential Risks for Affected Individuals?
The main risk is credential reuse. Many people use the same password across multiple sites, so a leaked forum password can unlock email, banking, or social media accounts elsewhere. Attackers routinely run leaked credential lists against other services, a technique known as credential stuffing.
The exposed email addresses also enable phishing. Someone holding a real email address paired with a previously used password can craft convincing messages that appear to come from services the victim actually uses. Even users whose forum passwords were unique may face targeted phishing attempts.
Because CrackingForum was itself a cracking community, the leaked hashes faced unusually motivated attackers with easy access to cracking tools. Weak or common passwords in the leak are likely to have been recovered in plain text already.
What Should You Do If You Were Affected?
If you had an account on CrackingForum, or if your email appears in this breach, take these steps:
Change your password on any account where you reused the CrackingForum password. Start with email and financial accounts, since email access lets an attacker reset other passwords.
Turn on two-factor authentication wherever it is offered, especially on your email account.
Check whether your email address appears in this breach using the search tool.
Be cautious with unexpected emails referencing your account, passwords, or login problems. Do not click links or enter credentials from unsolicited messages.
If you still use passwords that are short or dictionary-based, replace them with long, unique passwords, ideally managed through a password manager.
Because the breach dates back to 2016, the leaked credentials have circulated for years. If you have not changed affected passwords since then, assume they are already known to attackers and act accordingly.
