[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f2u77qa9mvaw9h":3},{"success":4,"breach":5},true,{"_id":6,"name":7,"title":8,"slug":9,"domain":10,"breachDate":11,"addedDate":12,"modifiedDate":12,"contentUpdatedAt":13,"source":14,"sourceUrl":15,"sourceUrls":16,"pwnCount":18,"affectedCount":18,"affectedCountStatus":19,"affectedCountLowerBound":20,"affectedCountUnit":21,"hasEnglishDescription":4,"severity":22,"dataClasses":23,"description":34,"seoTitle":35,"seoTitleEn":36,"seoDescription":35,"seoDescriptionEn":37,"logoUrl":38,"isVerified":4,"isSensitive":4,"isSpamList":39,"isMalware":39,"company":40},"68e3266eda11adda48825133","CannabisForum","Cannabis.com Data Breach","cannabiscom","cannabis.com","2014-02-05T00:00:00.000Z","2014-06-01T07:55:24.000Z","2026-07-18T23:47:04.153Z","Verified breach record","https:\u002F\u002Fsynscan.net\u002Fbreaches\u002Fcannabiscom",[15,17],"https:\u002F\u002Flogoutify.com\u002Fbreaches",227746,"known",null,"unknown","High",[24,25,26,27,28,29,30,31,32,33],"Dates of birth","Email addresses","Geographic locations","Historical passwords","Instant messenger identities","IP addresses","Passwords","Private messages","Usernames","Website activity","\u003Cp>\u003Cstrong>Cannabis.com data breach\u003C\u002Fstrong> is one of the historical events that show how extensive a risk area can be created by account information held in online community forums. The data set leaked from the vBulletin-based forum on the Cannabis.com domain in February 2014 affected 227,746 user accounts and approximately ten thousand private messages exchanged among users. The incident was not limited to the risk of email addresses and passwords; since account profiles, forum activity, and private correspondence were also included in the same data set, it posed a multi-layered risk to users in terms of identity, reputation, and account security.\u003C\u002Fp>\n\u003Cp>The main point to consider when evaluating the Cannabis.com leak is the sensitivity of the forum context. A user having an account in a particular community can lead to inferences that may have legal, social, or professional consequences in some countries. Therefore, checking a Cannabis.com account is not just about changing an old forum password; the association of the email address with other accounts, IP address history, reuse of old passwords, and private message content should be considered together.\u003C\u002Fp>\n\u003Ch2>Leaked Data Types and Risks\u003C\u002Fh2>\n\u003Cp>Among the verified data classes are birth dates, email addresses, geographic location information, old passwords, instant messaging IDs, IP addresses, passwords, private messages, usernames, and site activity. These fields can be risky on their own; when they appear together in the same account set, the likelihood that attackers will recognize individuals, profile them, and develop targeted phishing scenarios increases.\u003C\u002Fp>\n\u003Cp>Email addresses and usernames can be used to match a person's accounts across different sites. Password and old password fields can be tried based on the assumption that the user may have preferred the same or similar passwords on other services. IP addresses and geographic location information can reveal the approximate region of the account owner or past connection patterns. Profile information such as date of birth can make it easier to guess answers to authentication questions.\u003C\u002Fp>\n\u003Cp>Private messages are one of the most critical parts of this incident. Forum communications may include personal preferences, social relationships, business contacts, health-related implications, or thoughts that the user has not shared publicly. Attackers can use such texts for blackmail, reputational damage, targeted fraud, or social engineering. The site activity area also provides additional context regarding which topics are read, which forum sections are active, or how active the account is.\u003C\u002Fp>\n\u003Ch2>Verified Scope and Boundaries\u003C\u002Fh2>\n\u003Cp>The confirmed date for the Cannabis.com incident should be considered February 5, 2014, and the date it was added to the database is June 1, 2014. The number of affected unique accounts is 227,746. The data is associated with Cannabis.com's marijuana-themed vBulletin forum and circulated publicly after the leak. Since there is no attacker group verified with explicit attribution, the perpetrator information of the incident is not considered definite.\u003C\u002Fp>\n\u003Cp>The scope limit is also important. This incident concerns Cannabis.com forum accounts and user data linked to the forum; there is no verified area for payment cards, bank accounts, passports, official ID numbers, or direct financial transaction history. Since private messages and site activity are included among the data classes, the incident is severe in terms of privacy, but including unverified areas would mislead the user. Therefore, the risk assessment should be based solely on verified areas.\u003C\u002Fp>\n\u003Cp>The presence of approximately ten thousand private messages in the dataset creates an impact that cannot be measured solely by the number of accounts. For individuals who have registered on other forums or social accounts with the same email address, there is a chain risk. However, this does not mean that every visitor to Cannabis.com is affected; the risk is limited to users who have a forum account and whose data has been leaked.\u003C\u002Fp>\n\u003Ch2>User Groups at Risk\u003C\u002Fh2>\n\u003Cp>The highest risk group consists of people who were members of the Cannabis.com forum before 2014 or around that period, who used the same email address for other services, and who repeated the forum password on other accounts. In particular, trying old passwords on other accounts can pave the way for account takeover attempts even years later. People who reuse passwords with minor changes also carry a similar risk.\u003C\u002Fp>\n\u003Cp>Users who share their real name, location, birth date, or instant messaging account on the forum face a higher risk of identity association. People who do not want their forum membership to become visible due to work, family, health, legal situation, or personal preferences may face reputation and privacy risks. If private messages include phone numbers, addresses, work relationships, purchase intentions, or other personal details, the risk area extends beyond the forum account.\u003C\u002Fp>\n\u003Cp>An additional risk for users who register with a corporate email address is linking forum activity to their workplace identity. This situation can lead attackers to prepare more convincing phishing messages. If the username is the same across different platforms, forum data can be matched with social media, messaging accounts, or other community profiles.\u003C\u002Fp>\n\u003Ch2>Urgent Measures to Be Taken\u003C\u002Fh2>\n\u003Cp>If the email address linked to the Cannabis.com account is still in use, the priority is to change the password on all accounts that use the same or similar passwords. A unique, long, and random password should be chosen for each service; two-factor authentication should be enabled on accounts where possible. Even if the old forum password does not appear active today, the risk continues if it was used on other accounts in the past.\u003C\u002Fp>\n\u003Cp>The email account should also be protected, because leaked forum information is often used together with phishing attempts targeting the email account. The user should be cautious about messages referring to Cannabis.com or forum history, should not click on links directly, and should carefully review password reset notifications. Unexpected login alerts, new device notifications, and suspicious sessions should be checked through security settings.\u003C\u002Fp>\n\u003Cp>If there is personal information shared in private messages, the risk does not end merely with changing the password. The user should review other people, accounts, or communication channels mentioned in the messages; tighten privacy settings for phone numbers, addresses, usernames, or social media information that may have been exposed. If the same username is used on other platforms, it is helpful to limit search and profile visibility.\u003C\u002Fp>\n\u003Ch2>Long-Term Security Strategies\u003C\u002Fh2>\n\u003Cp>These types of old forum breaches can be used in phishing and account takeover attempts even years after the data has been released online. Therefore, users need to evaluate not only the accounts they had at the time of the incident but also all important accounts they have opened over the years with the same email address. Using a password manager, generating unique passwords for each account, and completely removing old passwords from archives are key to long-term protection.\u003C\u002Fp>\n\u003Cp>The most accurate strategy in terms of personal information is to share minimal data on forums and community sites. Fields such as date of birth, location, instant messaging ID, and real name should be left empty or have their visibility restricted if they are not mandatory. Choosing a username is also important; using the same username on many sites makes it easier to combine different data sets.\u003C\u002Fp>\n\u003Cp>On the corporate side, it should not be forgotten that employees may be targeted due to old forum leaks. Security teams should reduce the reuse of old passwords associated with employee emails, promote multi-factor authentication, and provide awareness training against phishing scenarios containing sensitive community membership information. Since old breach data can be used in new attacks, monitoring and password hygiene require continuity.\u003C\u002Fp>\n\u003Ch2>Record Control and User Action\u003C\u002Fh2>\n\u003Cp>A user who wants to understand whether they were affected by the Cannabis.com data leak should check their email address on a trusted verification screen. If the result is positive, this does not necessarily mean that the user currently has an active Cannabis.com account; it indicates that the email address was present in the 2014 forum data. Nevertheless, if the old password and username were used on other services, urgent security measures are needed.\u003C\u002Fp>\n\u003Cp>If the result is negative, it should not be overlooked that the same person may have registered with different email addresses. Old personal emails, work emails, and accounts opened with pseudonyms should be checked separately. Users who receive a positive result should also review their account recovery emails, security questions, and connected devices after completing the password change.\u003C\u002Fp>\n\u003Cp>The Cannabis.com breach shows that accounts used in sensitive communities should not be seen as ordinary forum accounts. The combination of email, password, IP address, and private messages poses a persistent risk in terms of identity association, social pressure, targeted phishing, and account takeover. The most effective approach is to fully retire the leaked password, strengthen critical accounts associated with the same email, and reassess whether personal information included in private messages still poses a risk today.\u003C\u002Fp>","","Cannabis.com Data Breach (227.7 Thousand Reported Records)","Cannabis.com Data Breach. 227.7 Thousand reported records were reported. Reported data: Dates of birth, Email addresses, Geographic locations. Review the…","\u002Fuploads\u002Flogo\u002Fcannabis_com.webp",false,{"name":41,"sector":42,"country":43,"website":10,"websiteArchiveUrl":35,"websiteStatus":35,"websiteCheckedAt":20},"Cannabis.com","Cannabis community forum","United States"]