Data breach
MPGH
- Records
- 2,463,705
- Breach date
- 22 October 2015Estimated
- Added
- 24 March 2025
What was exposed
3 types of data
- Usernames2,463,701
- IP addresses2,463,681
- Email addresses2,463,269
About this breach
In October 2015, MPGH.net, a large online forum dedicated to multiplayer game hacking and cheating, was breached through an exploit in its vBulletin forum software. The incident exposed records linked to roughly 2.46 million accounts, with an estimated attack date of October 22, 2015. The listing carries no claimed responsibility from any named actor, and no one has publicly taken credit. The data later surfaced in breach-tracking databases, where it was indexed and searchable for years afterward.
Limited public reporting: As of September 25, 2026, detailed company notices or major news coverage for this listing were limited in sources reviewed. The facts below rely primarily on the indexed fields plus any secondary sources cited.
Breach Timeline
October 22, 2015: Estimated date of the breach, as recorded in Mozilla Monitor.
October 26, 2015: The breach was verified and added to Mozilla Monitor's public breach database.
November 2015: vBulletin released a security patch following attacks on its own developers' site, according to CyberInsurance.com.
What Information Was Compromised?
Our analysis found the following data types in this breach: IP addresses (about 2.46 million), usernames or nicknames (about 2.46 million), and email addresses (about 2.46 million). Mozilla Monitor also lists passwords among the exposed data, and secondary reporting describes those credentials as salted password hashes rather than plain text.
Because the data came from the forum's central user database, the records cover nearly the full registered membership of the site before the attack.
Not every individual is affected by every type of data listed here.
What Are the Potential Risks for Affected Individuals?
The clearest risk is password reuse. If an MPGH.net member used the same password on other sites, attackers who obtain the hashed credentials could crack them and try those combinations elsewhere. Even salted hashes are not immune to determined cracking, particularly for weak or common passwords.
Email addresses paired with usernames also support targeted phishing. Criminals can craft convincing messages that reference a person's forum activity or gaming interests, hoping to trick recipients into revealing passwords or installing malware. The inclusion of IP addresses adds a smaller privacy concern, since they can reveal approximate locations or internet providers at the time of registration.
Because MPGH is a game-hacking community, the breach has an added wrinkle: some users may have accounts tied to game or cheat-related services, and compromise of those accounts can disrupt access to purchased tools or connected game profiles.
What Is MPGH Doing in Response?
Direct statements from the forum's operators about the breach were limited in sources reviewed as of September 25, 2026. However, CyberInsurance.com reports that MPGH.net reset all user passwords following the attack, a step meant to block direct access to member accounts using the stolen credentials.
What Should You Do If You Were Affected?
Change your MPGH.net password if you still use the account, and make it unique.
Change the password anywhere you reused the same or a similar password, starting with email and financial accounts.
Turn on two-factor authentication wherever the sites you use offer it.
Watch for phishing emails that reference gaming, cheats, or the forum itself, and avoid clicking links in unexpected messages.
Use a password manager to generate and store distinct passwords for every account.
