Data breach
Nulled
- Records
- 466,190
- Breach date
- 1 January 2016Estimated
- Added
- 1 December 2024
What was exposed
2 types of data · 4 more reported · 1 puts you at serious risk
- Email addresses466,190
- Passwords466,125
- UsernamesReported, not counted
- IP addressesReported, not counted
- Private messagesReported, not counted
- Purchase historyReported, not counted
Reported in the breach write-up; not counted in the analysed data.
About this breach
In 2016, the Nulled forum, a website widely known as a marketplace for stolen account details and hacking tutorials, was hacked and its database leaked online. The indexed dataset contains 466,190 rows, including 466,190 email addresses and 466,125 passwords. External reporting at the time described a much larger dump of the forum's full database, and the site went offline shortly after the leak became public.
Independent reporting filled in details about the scale of the incident. The BBC reported in May 2016 that email addresses and private messages of more than 470,000 members had leaked, and that the dump included invoices, usernames, PayPal addresses, IP addresses, and millions of forum posts and private messages. Researchers cited by the BBC said the forum ran message board software with known vulnerabilities and used a weak hashing algorithm to protect passwords. Mozilla Monitor dates the breach itself to May 6, 2016. The investigation team estimates the attack occurred earlier in 2016, and the dataset was added to its index on December 1, 2024. No individual or group has claimed the breach in the records; contemporary reporting noted that a Romanian group claimed responsibility, though the attackers' identity was never firmly established.
Breach Timeline
May 6, 2016: Mozilla Monitor records this as the date the Nulled breach occurred.
May 16, 2016: The BBC reports the leak of member emails and private messages, noting the site had been taken offline and described as undergoing "routine maintenance."
January 29, 2025: The FBI, with international partners, seized the Nulled.to domain as part of Operation Talent, a coordinated action against several hacking forums, according to Wikipedia.
What Information Was Compromised?
Our analysis found the following data types in this breach:
Email addresses, about 466,190 records
Passwords, about 466,125 records
Not every individual is affected by every type of data listed here.
Contemporaneous reporting indicates the full leaked database also contained usernames, IP addresses, private messages, PayPal addresses, purchase records, and invoices, though those fields are not part of the index for this listing.
What Are the Potential Risks for Affected Individuals?
The main risk from exposed email addresses and passwords is credential stuffing. Attackers take an email and password pair from one breach and try it on banking, shopping, and social media accounts, betting that the person reused the same password elsewhere. That risk persists years after a leak, because breached credential lists circulate widely.
The BBC also reported that some of the leaked data could be used to work out members' real identities if they had not taken steps to conceal them, since the dump contained private messages and activity records. Anyone whose real-world identity is linked to activity on a forum like Nulled faces potential embarrassment, blackmail attempts, or legal exposure depending on what those messages contain.
What Is Nulled Doing in Response?
Verified public responses were limited. The BBC reported that the site went offline after the leak, displaying a notice that it was undergoing "routine maintenance." No formal notice to members, breach notification, or remediation plan from the forum's operators was found in the sources reviewed. The domain was later seized by law enforcement in January 2025, which effectively ended the site's operation.
What Should You Do If You Were Affected?
Change the password for any account that used the same password as your Nulled account, starting with email and banking.
Turn on two-factor authentication wherever it is offered, especially for email, which protects password resets for other accounts.
Use unique passwords for every account. A password manager makes this practical.
Watch for phishing emails that reference your membership or the breach, and avoid clicking links in unexpected messages.
Consider checking whether your email address appears in this or other breach listings so you know which passwords to rotate.
