[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fnyugdcnpd2x4":3},{"success":4,"breach":5},true,{"_id":6,"name":7,"title":8,"slug":7,"domain":9,"breachDate":10,"addedDate":11,"modifiedDate":12,"contentUpdatedAt":13,"source":14,"sourceUrl":15,"sourceUrls":16,"pwnCount":17,"affectedCount":17,"affectedCountStatus":18,"affectedCountLowerBound":19,"affectedCountUnit":20,"hasEnglishDescription":4,"severity":21,"dataClasses":22,"description":27,"seoTitle":28,"seoTitleEn":29,"seoDescription":28,"seoDescriptionEn":30,"logoUrl":31,"isVerified":4,"isSensitive":32,"isSpamList":32,"isMalware":32,"company":33},"68e3266eda11adda48825109","benchmark","Benchmark Data Breach","benchmark.rs","2019-11-01T00:00:00.000Z","2023-01-01T01:50:43.000Z","2026-07-02T12:26:55.059Z","2026-07-18T23:44:01.287Z","Verified breach record and forum administrator statement","https:\u002F\u002Fforum.benchmark.rs\u002Fthreads\u002Fbenchmark-forum-kompromitovan-update.489760\u002F",[15],93343,"known",null,"unknown","Medium",[23,24,25,26],"Email addresses","IP addresses","Passwords","Usernames","\u003Cp>The Benchmark data breach is associated with the exposure of forum user registrations on Benchmark.rs, a Serbia-based technology news and forum site, in November 2019. In the LeakData record, this breach is tracked with 93,343 accounts. The verified data types are email addresses, IP addresses, usernames, and passwords. It is stated that the passwords were stored as plain MD5 hashes. Although this is not as direct as plaintext passwords, it poses a significant account security risk because MD5 is considered weak for modern password security.\u003C\u002Fp>\u003Cp>Benchmark is not a retail site; it is a news and discussion community used by technology enthusiasts, hardware users, and forum members. Therefore, the current retail classification provides the user with a misleading context. Email, username, IP, and password information used in forum accounts can especially pose a broader risk of identity matching and password testing if the same username is reused across different technology forums or gaming communities. Since names, phone numbers, addresses, or payment information have not been verified in this record, they are not included in the data fields.\u003C\u002Fp>\u003Ch2>Leaked Data Types and Risks\u003C\u002Fh2>\u003Cp>The types of data verified in the benchmark breach are email addresses, IP addresses, usernames, and passwords. The username is linked to the forum ID and, if the same nickname is used on other platforms, it can lead to connecting a person's online profiles. The email address identifies the account owner, the IP address can provide clues about the approximate connection region or account usage history. As for the password field, since it is stored only in MD5 format, there is a risk of being cracked if the password is weak or reused.\u003C\u002Fp>\u003Cp>The use of salt makes the direct bulk comparison of passwords more difficult; however, MD5 is a fast method that is no longer considered secure. Therefore, particularly short, predictable, or passwords seen in other breaches are at risk. Attackers may try the email, username, and password combination on different forums, email services, gaming platforms, or technology store accounts. Even if a forum account seems small, the impact of the breach increases if the same password is used elsewhere.\u003C\u002Fp>\u003Ch2>Verified Scope and Boundaries\u003C\u002Fh2>\u003Cp>The Benchmark record on LeakData is monitored at the account level for 93,343 accounts, and the incident date is recorded as November 1, 2019. The verified scope is associated with Benchmark.rs forum records. The administrator’s comments indicate that the breach may be related to an older instance of the forum software previously in use. Therefore, the incident should not be interpreted as a broader violation involving the technology news site's entire content management or payment systems.\u003C\u002Fp>\u003Cp>In this record, the verified data fields are email address, IP address, username, and password. Name, phone number, physical address, payment card, private message, forum post, or purchase history are not included as verified data fields. This restriction is maintained to avoid misleading the user with unnecessary claims. Nevertheless, since the password and IP information are present together, the record should be taken seriously in terms of account security and online profile matching.\u003C\u002Fp>\u003Ch2>User Groups at Risk\u003C\u002Fh2>\u003Cp>The first group at risk are users who have opened an account on the Benchmark.rs forum and those who use the same email or username in other technology communities. Usernames are often repeated in hardware, software, gaming, and technology forums. This situation can help an attacker link different profiles belonging to the same person. If the same password is also used on other forums or email accounts, the risk can directly turn into account takeover attempts.\u003C\u002Fp>\u003Cp>Technology forum users may occasionally share personal information in the context of hardware purchases, second-hand sales, warranties, service, or business accounts. Although these additional fields are not verified in this Benchmark record, the combination of email and IP address with the forum identity can be sufficient for targeted messages. Users who register with a work email should be especially careful if the same password has been used in work systems. Even if the forum account is old, password habits can affect new accounts.\u003C\u002Fp>\u003Ch2>Urgent Measures to Be Taken\u003C\u002Fh2>\u003Cp>Users who see a match in the Benchmark record should first check whether the password they used on their Benchmark.rs account has been reused on other accounts. If the same or a similar password has been used for email, social media, technology forums, gaming platforms, shopping sites, or work accounts, it should be changed immediately. New passwords should be unique for each account, and two-factor authentication should be enabled wherever possible.\u003C\u002Fp>\u003Cp>Users should also be cautious of suspicious messages coming from a forum name or an old username. A message may imply the user's previous nickname, technology interest, or IP-connected region information; this alone is not proof of reliability. Instead of clicking on links, log in through the known address, carefully review password reset alerts, and close unrecognized sessions. Old MD5-based passwords should not be reused on any account.\u003C\u002Fp>\u003Ch2>Long-Term Security Strategies\u003C\u002Fh2>\u003Cp>The benchmark incident shows that forum accounts can also have a significant impact on password security. Users should not reuse the same password across forum, gaming, technology, shopping, and social media accounts. Using a password manager, generating long and unique passwords for each service, and fully retiring old passwords is the strongest long-term solution. Reducing username repetition can also make it harder to link different community profiles to each other.\u003C\u002Fp>\u003Cp>From the perspective of forum administrators, old software examples and plugins should be regularly closed, password storage methods should be updated to current standards, and old user data should not be kept unnecessarily. Unsalted MD5 is no longer sufficient; stronger and slower password storage methods should be preferred. On the user side, old forum accounts should not be forgotten, and if possible, they should be closed or their passwords updated. An old forum breach, if there is password reuse, can affect important accounts used today.\u003C\u002Fp>\u003Ch2>Record Control and User Action\u003C\u002Fh2>\u003Cp>When querying a Benchmark data breach on LeakData, the result shows whether the entered email address is present in this verified Benchmark.rs forum data set. If a match is found, it indicates that the email, username, IP address, and salted MD5 password information may have been affected in this incident. This result does not mean a payment or identity document leak; however, it requires immediate checking of password reuse.\u003C\u002Fp>\u003Cp>Users of matched domains should update all accounts where they use the same password, check the login history on important accounts, and enable two-factor authentication. The absence of a match does not guarantee that the password is not present in other technology forums or password datasets; it only indicates that no match was found in this Benchmark record. This record has been limited to verified domains and organized to clearly convey the real password security risk in the context of forum accounts.\u003C\u002Fp>","","Benchmark Data Breach (93.3 Thousand Reported Records)","Benchmark Data Breach. 93.3 Thousand reported records were reported. Reported data: Email addresses, IP addresses, Passwords. Review the scope, risks, and…","\u002Fuploads\u002Flogo\u002Fbenchmark_rs.webp",false,{"name":34,"sector":35,"country":36,"website":9,"websiteArchiveUrl":28,"websiteStatus":28,"websiteCheckedAt":19},"Benchmark.rs","Technology news and forum","Serbia"]