Data breach
doomforum.com
- Records
- 1,032,407
- Breach date
- 1 January 2020Estimated
- Added
- 1 December 2024
What was exposed
2 types of data · 1 puts you at serious risk
- Email addresses1,032,407
- Passwords1,032,348
About this breach
A database containing more than one million user records from DoomForum.com, an online community forum for fans of the Doom video game series, has been indexed by the investigation team. According to our team, the dataset holds 1,032,407 rows, nearly all of them pairing an email address with a password. Our team estimates the breach occurred on or around January 1, 2020, though independent leak trackers have tied the data to April 2020. No hacking group has publicly claimed responsibility, and the forum's operators do not appear to have issued a public notice about the incident.
Limited public reporting: As of September 25, 2026, detailed company notices or major news coverage for this listing were limited in sources reviewed. The facts below rely primarily on the indexed fields plus any secondary sources cited.
Breach Timeline
April 2020: The leak-indexing service LeakCheck lists DoomForum.com in its database of breached sources, dated April 2020, with roughly one million entries.
April 24, 2020: RansomLook, a service that tracks leaked databases, recorded a Doomforum.com dataset of 1,032,639 entries on this date.
What Information Was Compromised?
Our analysis found the following data types in this breach:
Email addresses, present in all 1,032,407 records
Passwords, present in 1,032,348 records
Not every individual is affected by every type of data listed here.
The dataset appears to be a standard forum user export. No names, phone numbers, payment details, or government identifiers were reported in the indexed fields reviewed for this article.
What Are the Potential Risks for Affected Individuals?
The main risk from a forum leak of this kind is password reuse. Many people use the same password across multiple sites, so a password leaked from a gaming forum can open the door to email accounts, shopping sites, or social media profiles elsewhere.
Attackers commonly feed leaked email and password pairs into automated credential stuffing tools, which test them against dozens of other websites. Even a small success rate can produce working logins.
The exposed email addresses are also useful for phishing. Someone who knows you are a Doom community member can craft convincing messages that reference the game or the forum to trick you into clicking malicious links or handing over more credentials.
Because this dataset has circulated on leak-indexing platforms since 2020, it may have been available to criminals for years, which increases the chance it has already been used.
What Should You Do If You Were Affected?
Change your password on DoomForum.com if you still use the site.
If you reused that password anywhere else, change it there too, starting with your email account and any financial services.
Turn on two-factor authentication wherever it is offered, especially for your primary email account.
Watch for phishing emails that reference the forum or the game. Do not click unexpected links or download attachments.
Check whether other accounts have been compromised and review login activity for unfamiliar devices or locations.
Even if you no longer visit the forum, the leaked credentials may still unlock other accounts, so acting now is worthwhile.
