Data breach
SuperBetter Forums
- Records
- 34,060
- Breach date
- 1 January 2017Estimated
- Added
- 1 December 2024
What was exposed
2 types of data · 1 puts you at serious risk
- Email addresses34,060
- Passwords34,058
About this breach
A forum associated with SuperBetter, the mental wellness and goal-setting app created by game designer Jane McGonigal, was among hundreds of vBulletin-based forums whose user data was stolen and leaked in early 2017. According to our investigation team, the listing contains about 34,060 rows tied to the site, with email addresses and passwords making up nearly all of the exposed records. The breach itself was not an isolated attack on SuperBetter. It was part of a much larger campaign in which a hacker targeted forums running outdated versions of the vBulletin software.
The campaign was reported by INCIBE-CERT, the Spanish cybersecurity agency's incident response arm, which noted that a hacker claimed on Twitter to have stolen and published data from hundreds of thousands of forum accounts. The stolen information reportedly included email addresses, password hashes, and IP addresses. A list of affected forums, including forums.superbetter.com, was posted publicly on Pastebin alongside those of more than 120 other sites.
January to February 2017: A hacker claimed responsibility for stealing account data from hundreds of vBulletin forums, exploiting versions that had not been updated, according to INCIBE-CERT.
Shortly afterward: A Pastebin post listed forums.superbetter.com among the affected forums whose data had been leaked.
What Information Was Compromised?
Our analysis found the following data types in this breach: email addresses for 34,060 records and passwords for 34,058 records. Independent breach directories that track this incident describe the passwords as MD5-hashed and salted, and also list usernames among the exposed fields. Because the data came from forum registrations, the accounts likely reflect the usernames and email addresses people chose at the time rather than any account tied to the SuperBetter app itself.
Not every individual is affected by every type of data listed here.
What Are the Potential Risks for Affected Individuals?
The main risk from a forum breach like this is password reuse. If you used the same password on the SuperBetter forums as on your email, banking, or social media accounts, criminals can try those credentials elsewhere, a technique known as credential stuffing. Automated tools feed leaked email and password pairs into login pages across the internet until something works.
MD5 hashing, even with a salt, is considered weak by modern standards, which increases the chance that some passwords can be cracked. Exposed email addresses also feed into phishing campaigns, since attackers can craft messages that reference the forum to appear more convincing.
What Should You Do If You Were Affected?
If you had an account on the SuperBetter forums, take these steps:
Change your password anywhere you reused the forum password, starting with your email account. Email is the recovery key for most other services.
If you still use the forum or the SuperBetter app, set a new, unique password.
Turn on two-factor authentication wherever it is offered, especially for email and financial accounts.
Watch for phishing emails that mention the forum, SuperBetter, or account problems, and avoid clicking links in unexpected messages.
Limited public reporting: As of September 25, 2026, detailed company notices or major news coverage for this listing were limited in sources reviewed. The facts below rely primarily on the indexed fields plus any secondary sources cited.
