[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f2osl9dik9qtuf":3},{"success":4,"breach":5},true,{"_id":6,"name":7,"title":8,"slug":9,"domain":10,"breachDate":11,"addedDate":12,"modifiedDate":13,"contentUpdatedAt":14,"source":15,"sourceUrl":10,"sourceUrls":16,"pwnCount":17,"affectedCount":17,"affectedCountStatus":18,"affectedCountLowerBound":19,"affectedCountUnit":20,"hasEnglishDescription":4,"severity":21,"dataClasses":22,"description":26,"seoTitle":10,"seoTitleEn":27,"seoDescription":10,"seoDescriptionEn":28,"logoUrl":29,"isVerified":4,"isSensitive":4,"isSpamList":30,"isMalware":30,"company":31},"68e3266eda11adda48825164","crime-agency-vbulletin","CrimeAgency vBulletin Hacks Data Breach","crimeagency-vbulletin-hacks","","2017-01-19T00:00:00.000Z","2017-03-21T03:12:40.000Z","2026-07-02T12:29:03.590Z","2026-07-18T23:49:09.394Z","Third party breach",[],942044,"known",null,"unknown","High",[23,24,25],"Email addresses","Passwords","Usernames","\u003Cp>CrimeAgency vBulletin Hacks is not a breach belonging to a single site, but a collection of forum breaches that combines account data taken from multiple unpatched vBulletin forums. The record associated with attacks that took place in January 2016 affected approximately 942 thousand unique email addresses with usernames and mostly salted MD5 password hashes.\u003C\u002Fp>\u003Cp>This record should be described not as a company brand, but as a series of forum software violations covering around 140 forums. The risk for the user is that combinations of email, username, and password, for which the originating forum is not always clear, could be tried on other accounts.\u003C\u002Fp>\u003Ch2>Leaking Data Types and Risks\u003C\u002Fh2>\u003Cp>The data classes tracked in the CrimeAgency vBulletin Hacks record should be regarded as email addresses, password data, and usernames. Email addresses can be used for targeted phishing, password reset schemes, and account matching across different services. Password data directly increases the risk of account takeover, especially if the same password is reused on other services. Usernames can help link aliases across different platforms and customize social engineering messages.\u003C\u002Fp>\u003Cp>Usernames used on forum accounts can be repeated across different communities for a long time. If password hashes are weak, they can be cracked; if the same password is used on another forum, game, email, or social media account, the risk is not confined to a single forum.\u003C\u002Fp>\u003Ch2>Verified Scope and Boundaries\u003C\u002Fh2>\u003Cp>This record is a collection of multiple forum breaches known as CrimeAgency vBulletin Hacks. The scope includes email addresses, password data, and usernames. Private messages, payment information, official IDs, or the entire content of a specific forum should not be generalized for this record.\u003C\u002Fp>\u003Cp>Areas not present in this record should not be described as if they have leaked. Fields such as full payment card, official ID, private message, health data, bank information, or device content should only be included in the risk assessment when they are explicitly present in the record. The text is based on verifiable data classes and the known boundaries of the incident.\u003C\u002Fp>\u003Ch2>User Groups at Risk\u003C\u002Fh2>\u003Cp>Users who registered on vBulletin-based forums before 2016, people who use the same username on different forums, account owners who maintain old password patterns, and people who use their email address publicly on forums are at risk.\u003C\u002Fp>\u003Cp>Users who use the same email address on different services, repeat old passwords, do not separate work and personal accounts, or share phone and address information on multiple platforms are at higher risk. In data collection or B2B profile registrations, the risk should also be assessed based on the profile effect consolidated from different sources rather than a single account.\u003C\u002Fp>\u003Ch2>Urgent Measures to Be Taken\u003C\u002Fh2>\u003Cp>Users should update their old forum passwords and all accounts where the same password is used. Priority should be given to these accounts, especially if the same password was used for email, social media, and gaming accounts.\u003C\u002Fp>\u003Cp>Users in the positive match area should update their passwords on accounts where they use the same or similar passwords, enable two-factor authentication where possible, and check their recent sessions. For records that do not contain passwords but include communication or profile data, caution should be exercised against unexpected calls, offers, returns, partnerships, and verification messages.\u003C\u002Fp>\u003Ch2>Long-Term Security Strategies\u003C\u002Fh2>\u003Cp>In the long term, the habit of using a password manager, unique passwords, two-factor authentication, and removing unnecessary personal information from accounts reduces risk. Reusing the same email address across different platforms makes it easier to combine data from different breaches; using a separate email or alias for critical accounts can be considered.\u003C\u002Fp>\u003Cp>Although forum accounts seem low-risk, they can turn into data sets circulating for years. Users should use a unique password for each forum, close old accounts, and should not unnecessarily associate their pseudonyms with critical identities.\u003C\u002Fp>\u003Ch2>Record Control and User Action\u003C\u002Fh2>\u003Cp>LeakData check indicates whether the queried email address is found in this record. A positive result does not necessarily mean that all data fields definitely belong to that user; however, it is a sufficient warning for precautionary measures. A negative result only indicates that there is no match in this dataset and does not eliminate the possibility of appearing in other breaches.\u003C\u002Fp>\u003Cp>A positive result indicates that the email address was found in the CrimeAgency vBulletin forum collection. This result alone may not show which forum it came from; nonetheless, comprehensive action should be taken against password reuse.\u003C\u002Fp>","CrimeAgency vBulletin Hacks Data Breach (942 Thousand Reported Records)","CrimeAgency vBulletin Hacks Data Breach. 942 Thousand reported records were reported. Reported data: Email addresses, Passwords, Usernames. Review the scope…","\u002Fuploads\u002Flogo\u002Fcrime_agency_vbulletin.webp",false,{"name":32,"sector":33,"country":34,"website":10,"websiteArchiveUrl":10,"websiteStatus":10,"websiteCheckedAt":19},"CrimeAgency vBulletin Hacks","Forum Breach Collection","Global"]