[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f2dp4p44g6ntmw":3},{"success":4,"breach":5},true,{"_id":6,"name":7,"title":8,"slug":7,"domain":9,"breachDate":10,"addedDate":11,"modifiedDate":12,"contentUpdatedAt":13,"source":14,"sourceUrl":15,"sourceUrls":16,"pwnCount":19,"affectedCount":19,"affectedCountStatus":20,"affectedCountLowerBound":21,"affectedCountUnit":22,"hasEnglishDescription":4,"severity":23,"dataClasses":24,"description":35,"seoTitle":36,"seoTitleEn":37,"seoDescription":36,"seoDescriptionEn":38,"logoUrl":39,"isVerified":4,"isSensitive":4,"isSpamList":40,"isMalware":40,"company":41},"68e3266eda11adda48825127","boxee","Boxee Data Breach","forums.boxee.com","2014-03-29T00:00:00.000Z","2014-03-30T13:07:16.000Z","2026-07-09T17:18:48.867Z","2026-07-18T23:46:19.557Z","Third party breach","https:\u002F\u002Farstechnica.com\u002Finformation-technology\u002F2014\u002F04\u002Fhack-of-boxee-tv-exposes-password-data-messages-for-158000-users\u002F",[15,17,18],"https:\u002F\u002Fwww.helpnetsecurity.com\u002F2014\u002F04\u002F02\u002Fpasswords-messages-of-158k-boxeetv-users-leaked\u002F","https:\u002F\u002Fwww.welivesecurity.com\u002F2014\u002F04\u002F02\u002Fattack-on-samsungs-boxee-tv-service-leaks-158000-passwords-and-emails\u002F",158093,"known",null,"unknown","High",[25,26,27,28,29,30,31,32,33,34],"Dates of birth","Email addresses","Geographic locations","Historical passwords","Instant messenger identities","IP addresses","Passwords","Private messages","User website URLs","Usernames","\u003Cp>The Boxee data breach is related to the compromise of the Boxee forum database running on forums.boxee.com. The incident was recorded on March 29, 2014, and the confirmed impact is 158,093 user accounts. Boxee was a platform known for its media center software and social features for the living room television experience; the breach affected forum user data rather than the main media playback service.\u003C\u002Fp>\n\u003Cp>The verified data categories for this breach are quite extensive: birth dates, email addresses, geographic locations, past passwords, instant messaging IDs, IP addresses, passwords, private messages, user web addresses, and usernames. The exposure of forum data covering nearly two hundred tables indicates that the incident is not limited to just email and password risks. Due to private messages and password histories, this breach should be considered a sensitive data violation.\u003C\u002Fp>\n\u003Ch2>Leaked Data Types and Risks\u003C\u002Fh2>\n\u003Cp>In the Boxee breach, email addresses, usernames, IP addresses, birth dates, geographic locations, instant messaging IDs, user web addresses, passwords, past passwords, and private messages have been verified. They can be used for email and username account matching. Instant messaging IDs and user web addresses can make it easier to link a person with other profiles. IP and location fields provide context for previous sessions or regional access.\u003C\u002Fp>\n\u003Cp>The inclusion of private messages and password histories increases the risk. Private messages may contain personal correspondence, links, or information belonging to third parties. Since password history can show a user's previous password patterns, not only the password at the time of breach but also previously used variations should be considered risky. If the same password or a similar pattern is used on other accounts, attempts to hijack accounts may be made.\u003C\u002Fp>\n\u003Ch2>Verified Scope and Boundaries\u003C\u002Fh2>\n\u003Cp>The verified scope of this record is 158,093 accounts and ten data classes: birth dates, email addresses, geographic locations, past passwords, instant messaging IDs, IP addresses, passwords, private messages, user web URLs, and usernames. Phone number, payment card, physical address, or government ID are not among the verified data fields for this record. The description should be limited to Boxee forum data.\u003C\u002Fp>\n\u003Cp>Boxee's media center software and device ecosystem should be separated from forum membership data. This record does not prove that the in-device media library or TV viewing history has been leaked. The breach belongs to the forum database, and actions shown to the user should be planned based on the forum account, email security, private message content, and password history.\u003C\u002Fp>\n\u003Ch2>User Groups at Risk\u003C\u002Fh2>\n\u003Cp>There are users in the highest risk group who reuse the password they used on their Boxee forum account on other accounts as well. The same username, instant messaging ID, or personal website address can be used for years on older media center and technology forums. This situation can make it easier to link profiles from different periods and to make the user's online history more visible.\u003C\u002Fp>\n\u003Cp>Users with private message content also carry a privacy risk. If messages contain personal information, account links, device configurations, social accounts, or details belonging to third parties, these should be evaluated separately. Even if the forum is no longer actively used, old password patterns and profile links still pose a risk on other accounts.\u003C\u002Fp>\n\u003Ch2>Urgent Measures to Be Taken\u003C\u002Fh2>\n\u003Cp>Users who have matched should first specify the password they used on the Boxee forum and whether the same password has been repeated on other accounts. Since past passwords have also been exposed, not only the last password but also old password patterns should be abandoned. Email accounts, social media, forums, developer accounts, cloud storage, and work accounts should be prioritized to switch to unique passwords.\u003C\u002Fp>\n\u003Cp>Links shared in private messages, personal web addresses, instant messaging identities, or information belonging to third parties should be reviewed. Users should be cautious of messages that appear to be about fake account security, old forum notifications, or device software updates. Instead of logging in from incoming links, the relevant service should be accessed directly, two-step verification should be enabled on critical accounts, and account recovery information should be updated.\u003C\u002Fp>\n\u003Ch2>Long-Term Security Strategies\u003C\u002Fh2>\n\u003Cp>The Boxee incident shows that old technology forums and discontinued product communities can also pose a persistent security risk. Users should regularly review forum and device community accounts they no longer use. Accounts that can be closed should be closed, those that cannot be closed should use unique passwords, and unnecessary personal website addresses, messaging IDs, or location information should not be kept in profile fields.\u003C\u002Fp>\n\u003Cp>For forum administrators, such incidents indicate that areas like old database tables, private message archives, and password history need to be managed along with their retention periods. On the user side, a password manager, leaked password checks, multi-factor authentication, and old account cleanup should be implemented together. A breach involving password history also makes old habits risky.\u003C\u002Fp>\n\u003Ch2>Record Control and User Action\u003C\u002Fh2>\n\u003Cp>Finding a match with the email address in this record indicates that the user is included in the Boxee forum dataset. The user should first determine which username, password, and profile information they used on the forum; then they should check whether the same username, instant messaging ID, or web address is connected to other accounts. Due to password history, old variations should no longer be used.\u003C\u002Fp>\n\u003Cp>Matching does not indicate that in-device media content has leaked; however, private messages, password histories, and profile links in the forum database are a strong security warning. Using unique passwords, two-factor authentication, evaluating sensitive information in private messages, and closing old forum accounts reduce the risks of account takeover, profile matching, and privacy that may arise from the Boxee breach.\u003C\u002Fp>","","Boxee Data Breach (158.1 Thousand Reported Records)","Boxee Data Breach. 158.1 Thousand reported records were reported. Reported data: Dates of birth, Email addresses, Geographic locations. Review the scope…","\u002Fuploads\u002Flogo\u002Fforums_boxee_com.webp",false,{"name":42,"sector":43,"country":44,"website":9,"websiteArchiveUrl":36,"websiteStatus":36,"websiteCheckedAt":21},"Boxee","Media center software \u002F forum","United States"]