Data breach
psiho.com
- Records
- 889,066
- Breach date
- 1 January 2020Estimated
- Added
- 1 December 2024
What was exposed
2 types of data · 1 puts you at serious risk
- Email addresses889,066
- Passwords888,087
About this breach
A dataset containing the email addresses and passwords of roughly 889,000 people tied to psiho.com, a Serbian website that publishes articles on psychology, mental health, and self-improvement, has surfaced in the index. Our investigation team estimates the breach occurred on January 1, 2020, and indexed the listing on December 1, 2024. No hacking group has claimed responsibility.
The dataset was independently documented by the dark web monitoring firm InsecureWeb, which reported that a user named nulled121312 posted a leaked file containing about 885,000 user records on the Nulled forums on June 2, 2023. According to InsecureWeb, the file measured 12.2 MB and contained email addresses and passwords. InsecureWeb stated that it notified psiho.com of the exposure.
The two accounts of this incident differ on timing. The investigation team estimates the underlying breach occurred in 2020, while the leak file itself appeared on a public forum in 2023. Data that is leaked years after an estimated breach date is common, since copies of stolen databases often circulate privately before they are published. It is not possible to confirm from available sources when the data was actually stolen.
Limited public reporting: As of September 25, 2026, detailed company notices or major news coverage for this listing were limited in sources reviewed. The facts below rely primarily on the indexed fields plus any secondary sources cited.
Breach Timeline
June 2, 2023: A user posting as nulled121312 published a file with about 885,000 user records on the Nulled forums, according to InsecureWeb.
June 28, 2023: InsecureWeb published a summary of the breach and said it had notified psiho.com.
What Information Was Compromised?
Our analysis found the following data types in this breach:
Email addresses: 889,066
Passwords: 888,087
Not every individual is affected by every type of data listed here.
InsecureWeb's report describes the leaked file as containing email addresses and passwords, which matches the data types recorded in the index. No other data types, such as names, phone numbers, or payment details, were reported in either source.
What Are the Potential Risks for Affected Individuals?
Email and password combinations are the raw material for account takeover. If you used the same password on psiho.com and on other services, attackers who hold this dataset can try those credentials against email providers, social media, banking sites, and shopping accounts. This technique, called credential stuffing, works because many people reuse passwords across sites.
Even without password reuse, the exposure of an email address invites targeted phishing. Criminals can send messages that appear legitimate because they reference real accounts or services, then trick recipients into revealing additional information or installing malware. If the exposed password also protects your primary email account, the risk is greater, since attackers who gain control of an inbox can reset passwords for many other services.
What Should You Do If You Were Affected?
Change your psiho.com password immediately, and change it anywhere else you used the same or a similar password.
Use a unique, strong password for every account. A password manager makes this practical.
Turn on two-factor authentication wherever it is offered, especially for email and financial accounts.
Watch for phishing emails that reference psiho.com or your accounts, and do not click links or open attachments in unexpected messages.
Monitor your accounts for unfamiliar logins or password reset requests you did not initiate.
