[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f2wx316zt06yqq":3},{"success":4,"breach":5},true,{"_id":6,"name":7,"title":8,"slug":9,"domain":10,"breachDate":11,"addedDate":12,"modifiedDate":13,"contentUpdatedAt":13,"source":14,"sourceUrl":15,"sourceUrls":16,"pwnCount":17,"affectedCount":17,"affectedCountStatus":18,"affectedCountLowerBound":19,"affectedCountUnit":20,"hasEnglishDescription":4,"severity":21,"dataClasses":22,"description":27,"seoTitle":15,"seoTitleEn":28,"seoDescription":15,"seoDescriptionEn":29,"logoUrl":30,"isVerified":4,"isSensitive":31,"isSpamList":31,"isMalware":31,"company":32},"68e3266eda11adda4882512e","breach-forums-clone","BreachForums Clone Data Breach","breachforums-clone","breachforums.vc","2023-06-17T00:00:00.000Z","2023-06-25T05:47:36.000Z","2026-07-29T11:40:53.262Z","Third party breach","",[],4204,"known",null,"unknown","Low",[23,24,25,26],"Email addresses","IP addresses","Passwords","Usernames","\u003Cp>BreachForums Clone is associated with one of the imitation forums using the name BreachForums, which had been previously shut down. The incident in June 2023 exposed over 4,000 records, including email addresses, IP addresses, usernames, and Argon2 password hashes.\u003C\u002Fp>\u003Cp>This record should not be confused with the original BreachForums breach. The scope is clone forum data associated with the domain breachforums.vc. Due to the nature of the forum, username and IP address matching may lead to the linking of pseudonyms with other security communities or forum accounts.\u003C\u002Fp>\u003Ch2>Leaked Data Types and Risks\u003C\u002Fh2>\u003Cp>The data classes tracked in the BreachForums Clone registration should be treated as email addresses, IP addresses, password data, and usernames. Email addresses can be used for targeted phishing, password reset schemes, and account matching across different services. IP addresses can provide indirect clues about access location, network provider, or device usage. Password data, especially if the same password is reused on other services, directly increases the risk of account compromise. Usernames can help link pseudonyms across different platforms and personalize social engineering messages.\u003C\u002Fp>\u003Cp>Although Argon2 password hashes are a modern form of protection, the risk continues with weak or reused passwords. When the IP address and username are found together, users' pseudonymous forum identity can be linked to their real email or access location.\u003C\u002Fp>\u003Ch2>Verified Scope and Boundaries\u003C\u002Fh2>\u003Cp>This record is limited to the breachforums.vc domain and the June 2023 clone forum incident. The scope includes email, IP address, password hashes, and usernames. Private messages, payment information, or data from different BreachForums versions should not be combined with this record.\u003C\u002Fp>\u003Cp>Fields that are not present in this record should not be described as if they have leaked. Fields such as full card number, account password, official ID, private message, device content, or health information should only be added to the risk assessment if they are explicitly included in the record. The text has been constructed based on verifiable data classes and the known boundaries of the incident.\u003C\u002Fp>\u003Ch2>User Groups at Risk\u003C\u002Fh2>\u003Cp>This clone is at risk for users who register on the forum, people who use the same nickname on different forums, account owners who use the same email address repeatedly on security or cybercrime forums, and those who use the same password on other platforms.\u003C\u002Fp>\u003Cp>Users who use the same email address across different services, repeat their old passwords, and share phone and address information on a large number of shopping or community accounts are at higher risk. The link between a pseudonym and the real identity in corporate or community accounts can create additional social engineering risks.\u003C\u002Fp>\u003Ch2>Urgent Measures to Be Taken\u003C\u002Fh2>\u003Cp>Users should change the password they use on this forum and other accounts where they use the same password pattern. People who use the same username in different places should assess the risk of profile matching and use different credentials for critical accounts.\u003C\u002Fp>\u003Cp>Users in the positive match area should update their passwords on accounts where they use the same or similar passwords, enable two-factor authentication where possible, and check recent sessions. Caution should be exercised against unexpected calls, deliveries, returns, support, and verification messages on records containing phone numbers, addresses, payment information, or sensitive community information.\u003C\u002Fp>\u003Ch2>Long-Term Security Strategies\u003C\u002Fh2>\u003Cp>In the long term, the habit of using a password manager, unique passwords, two-factor authentication, and removing unnecessary personal information from accounts reduces risk. Reusing the same email address across different platforms makes it easier to combine data from different breaches; using a separate email or alias for critical accounts can be considered.\u003C\u002Fp>\u003Cp>Email, username, and IP context can easily be combined in forum accounts. If users want to protect their pseudonyms, they should use a separate email, a unique password, and minimal profile information for each community.\u003C\u002Fp>\u003Ch2>Record Control and User Action\u003C\u002Fh2>\u003Cp>LeakData check indicates whether the queried email address is found in this record. A positive result does not necessarily mean that all data fields definitely belong to that user; however, it is a sufficient warning for precautionary measures. A negative result only indicates that there is no match in this dataset and does not eliminate the possibility of appearing in other breaches.\u003C\u002Fp>\u003Cp>A positive result indicates that the email address was found in the BreachForums Clone record. This result does not mean that all data from the original forum was affected; action should only be taken for these clone forum records.\u003C\u002Fp>","BreachForums Clone Data Breach (4.2 Thousand Reported Records)","BreachForums Clone Data Breach. 4.2 Thousand reported records were reported. Reported data: Email addresses, IP addresses, Passwords. Review the scope, risks…","\u002Fuploads\u002Flogo\u002Fbreachforums_vc.webp",false,{"name":33,"sector":34,"country":35,"website":10,"websiteArchiveUrl":36,"websiteStatus":37,"websiteCheckedAt":38},"BreachForums Clone","Cybercrime Forum Clone","Global","https:\u002F\u002Fweb.archive.org\u002Fweb\u002F20230701132922\u002Fhttps:\u002F\u002Fbreachforums.vc\u002F","archived","2026-07-29T11:30:22.391Z"]