Data breach
hackforums.net
- Records
- 194,380
- Breach date
- 25 June 2011Estimated
- Added
- 4 March 2025
What was exposed
1 type of data · 5 more reported
- Email addresses1
- PasswordsReported, not counted
- UsernamesReported, not counted
- Dates of birthReported, not counted
- IP addressesReported, not counted
- WebsitesReported, not counted
Reported in the breach write-up; not counted in the analysed data.
About this breach
In June 2011, HackForums.net, an online forum dedicated to hacking and computer security discussions, suffered a data breach in which attackers obtained personal information belonging to forum members. The listing contains 194,380 rows of user records, with an estimated attack date of June 25, 2011. The breach was carried out by the hacktivist group LulzSec as the closing act of its self-described "50 days of lulz" campaign, during which the group released data stolen from several organizations, including AT&T and the game Battlefield Heroes. As Wikipedia's entry on Hack Forums records, LulzSec published the forum data on June 25, 2011, alongside material from its other targets.
Limited public reporting: As of September 25, 2026, detailed company notices or major news coverage for this listing were limited in sources reviewed. The facts below rely primarily on the indexed fields plus any secondary sources cited.
June 25, 2011: LulzSec publicly released the HackForums.net user data as part of its final "50 days of lulz" dump, according to Wikipedia and contemporaneous reporting.
June 2011: The Hacker News reported on the release, noting a file described as roughly 200,000 HackForums.net user details.
What Information Was Compromised?
Our analysis found the following data types in this breach: email addresses.
External records of the leak, including Mozilla Monitor's breach entry for HackForums, list additional exposed data: usernames, passwords, dates of birth, IP addresses, instant messenger identities, social connections, spoken languages, time zones, user website URLs, and website activity.
The investigation team did not determine how many of these records contain a valid email address, so that count is unknown.
Not every individual is affected by every type of data listed here.
What Are the Potential Risks for Affected Individuals?
The main risk is account compromise through password reuse. Many people use the same password across multiple websites, so a password exposed in a 2011 forum leak can still unlock a current email, banking, or social media account if it was never changed. Attackers routinely run "credential stuffing" attacks, feeding leaked email and password pairs into login pages across the internet.
Because the leak also included dates of birth, IP addresses, and website activity, affected users face an elevated risk of targeted phishing. A message that references details only the site and the attacker know, such as a user's posting activity or registration information, can appear more convincing than ordinary spam.
There is also a privacy concern specific to this forum. HackForums.net was a hacking community, and membership itself was sensitive for some users. The public release of member emails and usernames more than a decade ago means that association remains searchable today.
What Should You Do If You Were Affected?
If you had a HackForums.net account, check whether your email address appears in this breach.
Change your password on HackForums.net if the account still exists, and on any other site where you reused the same password.
Use a unique, strong password for every important account, and consider a password manager to keep track of them.
Turn on two-factor authentication wherever it is offered, especially for email, which protects access to your other accounts.
Be cautious with emails referencing your forum membership or posting history. Attackers can use leaked details to make messages look legitimate. Avoid clicking links or entering credentials through email links.
