[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fd0wii6mt4iil":3},{"success":4,"breach":5},true,{"_id":6,"name":7,"title":8,"slug":9,"domain":10,"breachDate":11,"addedDate":12,"modifiedDate":13,"contentUpdatedAt":14,"source":15,"sourceUrl":16,"sourceUrls":17,"pwnCount":18,"affectedCount":18,"affectedCountStatus":19,"affectedCountLowerBound":20,"affectedCountUnit":21,"hasEnglishDescription":4,"severity":22,"dataClasses":23,"description":27,"seoTitle":16,"seoTitleEn":28,"seoDescription":16,"seoDescriptionEn":29,"logoUrl":30,"isVerified":4,"isSensitive":4,"isSpamList":31,"isMalware":31,"company":32},"68e3266eda11adda488251e7","forum-community","ForumCommunity Data Breach","forumcommunity","forumcommunity.net","2016-06-01T00:00:00.000Z","2018-12-05T05:04:45.000Z","2026-07-02T12:26:55.059Z","2026-07-18T23:51:10.953Z","Third party breach","",[],776648,"known",null,"unknown","High",[24,25,26],"Email addresses","Passwords","Usernames","\u003Cp>The ForumCommunity data breach is an account data leak experienced in mid-2016 by the Italy-based forum creation and community hosting service. The verified scope is 776,648 unique email accounts. The leaked fields are email addresses, usernames, and password data. It has been reported that the passwords were found in unsalted MD5 hash format. This situation poses a high risk for weak and reused passwords, even though it is not as direct as a plain text password leak.\u003C\u002Fp>\u003Cp>In forum hosting services like ForumCommunity, users often use the same email address, the same username, and similar password patterns for years. Therefore, the incident should not be seen as limited to just an old forum account. If the same username is used in different communities, the risk of digital identity matching increases when combined with email and password hashes. If the password in the forum account is reused on other services, the account can be used for credential stuffing attacks.\u003C\u002Fp>\u003Ch2>Leaking Data Types and Risks\u003C\u002Fh2>\u003Cp>The types of data confirmed in this record are email addresses, usernames, and passwords. The password field is tracked as unsalted MD5 hashes. MD5 is an old hashing method considered weak according to current security expectations. The absence of salt increases the risk further; because users with the same password may have the same hash, and comparison with precomputed password lists can yield faster results.\u003C\u002Fp>\u003Cp>The combination of email address and username can help attackers match accounts across different forums, games, social media, or content platforms. If the username has remained unchanged for years, an old ForumCommunity account can be linked to other digital profiles. If password hashes are cracked, the same password can be tried on other accounts. Therefore, the incident should be given high priority in terms of account security, even if the number of data fields seems small.\u003C\u002Fp>\u003Ch2>Verified Scope and Boundaries\u003C\u002Fh2>\u003Cp>The number of verified unique emails is 776,648. The event date is approximately mid-2016, and the registration date is tracked as June 1, 2016. The registration is associated with the ForumCommunity domain forumcommunity.net, and the service focuses on allowing users to create forums and manage community accounts. Verified fields consist of email, username, and password hashes.\u003C\u002Fp>\u003Cp>In this record, phone number, physical address, date of birth, payment card, bank account, official ID document, private message content, or forum message texts are not among the verified data fields. Users should assess the risk within this limit. The main impact of the incident is the weak protection of password hashes, the possibility of usernames matching with other profiles, and the same password being tried on different accounts.\u003C\u002Fp>\u003Ch2>User Groups at Risk\u003C\u002Fh2>\u003Cp>The people at the highest risk are users who reuse the password they use on their ForumCommunity account on other accounts as well. If the same password is used for email accounts, game accounts, social media profiles, other forums, or shopping sites, attackers may try the compromised passwords on different services. Even if old forum passwords are forgotten, they may continue to exist on other accounts.\u003C\u002Fp>\u003Cp>There is additional risk for people who use the same username in different communities. Forum usernames often become a permanent part of a person's online identity. A username leaked along with an email address can make it easier for attackers to find the same person on other platforms. People who use the same nickname in hobby, gaming, technology, or local community accounts should take this connection into consideration.\u003C\u002Fp>\u003Ch2>Urgent Measures to Be Taken\u003C\u002Fh2>\u003Cp>The password that may have been used on the ForumCommunity account should be changed immediately. If the same or a similar password exists on other accounts, all of them should switch to a unique and long password. The email account should be prioritized for protection, because password reset links for other accounts mostly arrive in the email inbox. If two-step verification is not enabled on the email account, it should be activated.\u003C\u002Fp>\u003Cp>Users should be cautious of messages coming from the old forum or community name. If a link requests information under the pretext of opening an old account, verifying a profile, viewing private messages, receiving a reward, or renewing a password, it should be checked through the official domain. Review the session history and security notifications on other platforms where you use the same username. Creating a different password for each account with a password manager is the most effective defense after this incident.\u003C\u002Fp>\u003Ch2>Long-Term Security Strategies\u003C\u002Fh2>\u003Cp>The ForumCommunity incident shows that old forum accounts can pose a security risk even years later. Users should use unique passwords for hobbies, forums, games, and community accounts in the long term. Accounts that are no longer used should be closed, and strong passwords and two-factor authentication should be preferred for active accounts. Using the same email address across communities can make it easier to aggregate different breaches.\u003C\u002Fp>\u003Cp>The key lesson for service providers is that passwords should not be stored using weak methods such as unsalted MD5. A unique salt value for each user, strong and slow password hashing algorithms, regular security updates, and the principle of data minimization are mandatory for community platforms. Even if forum services are not financial services, email, username, and password data can create a risk that may spill over to other accounts.\u003C\u002Fp>\u003Ch2>Record Control and User Action\u003C\u002Fh2>\u003Cp>If your email address appears in this record, check the password you use for your ForumCommunity account and other accounts where the same password is repeated. Even if you don't remember the old password, consider similar password patterns from the same period. Switch to unique passwords for your email, social media, gaming, forum, and shopping accounts. If you see an unfamiliar login, unexpected password reset notification, or suspicious message coming under an old forum name, check the account's security settings.\u003C\u002Fp>\u003Cp>ForumCommunity has not verified payment, address, or identity document fields in the data breach; however, email, username, and unsalted MD5 password hashes pose a sufficiently serious risk to account security. The most appropriate action is to terminate password reuse, secure the email account strongly, review other platforms where the same username is used, and prevent old forum accounts from creating risks on new accounts.\u003C\u002Fp>","ForumCommunity Data Breach (776.6 Thousand Reported Records)","ForumCommunity Data Breach. 776.6 Thousand reported records were reported. Reported data: Email addresses, Passwords, Usernames. Review the scope, risks, and…","\u002Fuploads\u002Flogo\u002Fforumcommunity_net.webp",false,{"name":33,"sector":34,"country":35,"website":10,"websiteArchiveUrl":16,"websiteStatus":16,"websiteCheckedAt":20},"ForumCommunity","Forum Hosting","Italy"]