[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fu3veeki0lzra":3},{"success":4,"breach":5},true,{"_id":6,"name":7,"title":8,"slug":9,"domain":10,"breachDate":11,"addedDate":12,"publishedAt":12,"modifiedDate":13,"contentUpdatedAt":12,"source":14,"sourceUrl":15,"sourceUrls":16,"pwnCount":20,"affectedCount":20,"affectedCountStatus":21,"affectedCountLowerBound":22,"affectedCountUnit":23,"hasEnglishDescription":4,"contentLocale":24,"availableLocales":25,"translations":27,"severity":30,"dataClasses":31,"description":37,"seoTitle":38,"seoDescription":39,"logoUrl":40,"isVerified":41,"isSensitive":4,"isSpamList":41,"isMalware":41,"company":42},"a425ff17e00ae172eb7bafb5","Horse & Hound","Horse & Hound Forum 2017 Associated Dataset","horse-and-hound-forum-2017","horseandhound.co.uk","2017-01-01T00:00:00.000Z","2026-08-31T21:00:38.182Z","2026-09-17T19:37:30.621Z","Sealed third-party forum dataset with two public catalogue bindings and historical domain metadata","https:\u002F\u002Fbreachera.com\u002F",[15,17,18,19],"https:\u002F\u002Fleak-lookup.com\u002Fbreaches#horseandhound-co-uk","https:\u002F\u002Fwww.horseandhound.co.uk\u002F","https:\u002F\u002Fweb.archive.org\u002Fcdx\u002Fsearch\u002Fcdx?url=forums-secure.horseandhound.co.uk&from=2016&to=2018&output=json&filter=statuscode:200",94876,"known",null,"records","en",[24,26],"tr",{"en":28,"tr":29},{"slug":9},{"slug":9},"Medium",[32,33,34,35,36],"Email addresses","Usernames","IP addresses","Password hashes","Salts","\u003Cp>This record documents a dataset labelled January 2017 and associated with the Horse &amp; Hound brand, the \u003Ccode>horseandhound.co.uk\u003C\u002Fcode> domain, and the former \u003Ccode>forums-secure.horseandhound.co.uk\u003C\u002Fcode> forum service. It is not presented as a verified security incident. No Horse &amp; Hound notice was found that binds the inspected archive to a specific incident, so \u003Ccode>isVerified=false\u003C\u002Fcode> is required. January 1, 2017 is only the technical representation of month-level precision and does not assert that an incident occurred on that exact day. The number of unique affected people is unknown, so \u003Ccode>pwnCount\u003C\u002Fcode> remains null.\u003C\u002Fp>\n\u003Cp>The event association comes from two separate public catalogues. BreachEra lists Horse and Hound, \u003Ccode>horseandhound.co.uk\u003C\u002Fcode>, the year 2017, a scope of 95,337 records, and the classes email addresses, IP addresses, usernames, and passwords in one row. Leak-Lookup reports 95,338 records for the same domain and lists username, email address, IP address, password, and salt columns in its statistics schema. The one-record difference between those catalogues is fully explained by one non-data preamble record in the sealed source. No data was selected or expanded merely to approach a catalogue total.\u003C\u002Fp>\n\u003Cp>The inspected \u003Ccode>HorseAndHound_BF.7z\u003C\u002Fcode> archive is 4,529,396 bytes and is sealed with SHA-256 \u003Ccode>ee05e8…5352\u003C\u002Fcode>. A complete 7z integrity test passed. Its principal member is named \u003Ccode>Forums-secure.horseandhound.co.uk_vb_January_2017.txt\u003C\u002Fcode>, is 8,868,144 bytes, and has SHA-256 \u003Ccode>b69419…7ca2\u003C\u002Fcode>. The source contains 95,338 physical records: one preamble and 95,337 data records. A separate 441-byte generic distribution note has no row-level email field and was closed as non-email metadata rather than being used to widen the source.\u003C\u002Fp>\n\u003Cp>The principal source is not an ordinary CSV with an explicit header. Its records resemble a colon-delimited vBulletin representation with variable widths because usernames can themselves contain colons. The review used the sole 32-character hexadecimal password digest in each data record as a structural anchor and measured the email-shaped field two positions before that anchor. The rule is structurally available for every one of the 95,337 data records. Nevertheless, field authority is inferred instead of named by a header, so the safety policy applies a higher admission threshold.\u003C\u002Fp>\n\u003Cp>Two independent compiled Go parsers processed the same complete member set using separate implementations and produced byte-identical occurrence and canonical streams. Both reported 94,917 accepted occurrences, 94,876 unique canonical results, 41 duplicate occurrences, 390 rejected nonblank values, and 30 blank slots. Coverage of the selected field is about 99.56 percent, while the strongest alternative email-shaped field contains only 90 candidates. These measurements support a strong inference, but mapping-admission v3 requires at least 100,000 accepted occurrences for an inferred mapping.\u003C\u002Fp>\n\u003Cp>The observed 94,917 occurrences are 5,083 below that mandatory minimum. The gate therefore closed with \u003Ccode>INFERENCE_OCCURRENCES_TOO_SMALL\u003C\u002Fcode>. The threshold was not reduced, other fields were not added to fit a catalogue count, and the 94,876 canonical results were not published as a count of affected people. This metadata record does not mean that any email relationship was imported: \u003Ccode>canonicalEmailCount\u003C\u002Fcode> is null, \u003Ccode>importedRecordCount=0\u003C\u002Fcode>, and processing remains pending. No READY package, import job, or Mongo email relationship may be created unless mapping admission later succeeds.\u003C\u002Fp>\n\u003Cp>A live global comparison was performed only as an audit. Of the inferred canonical set, 73,670 values already existed in the global email index and 21,206 did not; the matches were distributed across 798 breach identifiers. That distribution did not identify one existing record as the owner of the Horse &amp; Hound source, and no previous import job was bound by the same source key, archive SHA, canonical SHA, or filename identity. An overlap does not independently prove that an address belongs to this forum. It shows only that the same canonical value appears in other datasets.\u003C\u002Fp>\n\u003Cp>Wayback CDX metadata, checked without downloading archived page content, confirms successful captures for the secure forum subdomain during 2017. The current official Horse &amp; Hound domain also supports the service identity. In contrast, no exact entry was found in public breach source or NiamonX, and no first-party incident disclosure was identified. Those negative checks are not proof of absence; they define the verification boundary. The record therefore keeps attribution cautious, makes no whole-event completeness claim, and should be reassessed if a first-party notice or an explicit source schema becomes available.\u003C\u002Fp>","Horse & Hound Forum 2017 Associated Dataset (94.9 Thousand Records)","The unverified event association and closed import-mapping gate for the dataset linked to the Horse & Hound forum in January 2017.","\u002Fuploads\u002Flogo\u002Fhorseandhound_co_uk.webp",false,{"name":7,"sector":43,"country":44,"website":18,"websiteArchiveUrl":45,"websiteStatus":45,"websiteCheckedAt":22},"Media","United Kingdom",""]