Data breach
uTorrent
- Records
- 394,770
- Breach date
- 14 January 2016Estimated
- Added
- 17 March 2025
What was exposed
3 types of data · 1 more reported
- Usernames394,758
- Email addresses394,688
- IP addresses393,385
- PasswordsReported, not counted
Reported in the breach write-up; not counted in the analysed data.
About this breach
An attacker accessed the forum database behind uTorrent, the popular BitTorrent client, in early 2016, exposing records tied to nearly 400,000 forum accounts. According to our investigation team, the dataset associated with this incident contains about 394,770 rows, with email addresses, nicknames, and IP addresses appearing throughout. External reporting indicates the forum ran on IP.Board software provided by Invision Power Services, and that the intrusion appears to have reached the forum through the vendor.
The breach came to light months later. In a security advisory reported by Tripwire, BitTorrent said it learned of the issue on June 6, 2016, and that an attacker had downloaded a list of the forum's users, which contained more than 385,000 registered accounts. uTorrent urged forum members to change their passwords, and the forum vendor made backend changes intended to prevent the leaked password hashes from being used against other accounts.
January 14, 2016: The estimated date of the intrusion, based on external breach tracking of the uTorrent forum.
June 6, 2016: BitTorrent became aware of a security issue involving the vendor that powered its forums and disclosed the incident.
What Information Was Compromised?
Our analysis found the following data types in this breach:
Email addresses (about 394,688 records)
Nicknames (about 394,758 records)
IP addresses (about 393,385 records)
Reporting on the incident also indicates the forum database contained password hashes. Tripwire described a set of salted SHA1 hashed passwords associated with roughly 34,000 users, while other external accounts of the breach describe unsalted MD5 password hashes in the wider forum database. The exact password protections used across all records could not be fully verified.
Not every individual is affected by every type of data listed here.
What Are the Potential Risks for Affected Individuals?
The combination of email addresses, usernames, and IP addresses is valuable to attackers even without usable passwords. People whose details appear in the dataset may face:
Phishing emails that use real usernames and forum context to look convincing
Credential stuffing, where attackers test email and password pairs from this breach against other websites, since many people reuse passwords
Targeted spam built around the exposed email addresses
Privacy exposure through the link between an email address, a chosen nickname, and an IP address
If leaked password hashes could be cracked, any accounts where users reused the same password would be at elevated risk.
What Is uTorrent Doing in Response?
After learning of the incident in June 2016, uTorrent advised all forum users to change their passwords, according to the advisory reported by Tripwire. The company said it was working with Invision Power Services to determine whether attackers had accessed additional information. The vendor also made backend changes designed to ensure the forum's password hashes could not be abused as an attack vector. We did not find evidence of a more recent public statement from the company about this specific incident as of the research date for this article.
What Should You Do If You Were Affected?
If you used the uTorrent forums around 2016, take these steps:
Change your uTorrent forum password immediately, and change it anywhere else you reused it.
Use a unique, strong password for each account, ideally with a password manager.
Turn on two-factor authentication wherever it is offered, especially for your primary email account.
Watch for phishing. Be cautious with emails that reference uTorrent, BitTorrent, or file sharing and ask you to log in or click links.
Check whether your email address appears in this breach.
