[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f294kmhvzb6qie":3},{"success":4,"breach":5},true,{"_id":6,"name":7,"title":8,"slug":7,"domain":9,"breachDate":10,"addedDate":11,"modifiedDate":12,"contentUpdatedAt":13,"source":14,"sourceUrl":15,"sourceUrls":16,"pwnCount":19,"affectedCount":19,"affectedCountStatus":20,"affectedCountLowerBound":21,"affectedCountUnit":22,"hasEnglishDescription":4,"severity":23,"dataClasses":24,"description":29,"seoTitle":30,"seoTitleEn":31,"seoDescription":30,"seoDescriptionEn":32,"logoUrl":33,"isVerified":4,"isSensitive":34,"isSpamList":34,"isMalware":34,"company":35},"68e3266eda11adda4882527c","linux-forums","Linux Forums Data Breach","linuxforums.org","2018-05-01T00:00:00.000Z","2018-06-07T12:55:25.000Z","2024-09-04T23:38:20.000Z","2026-07-18T23:53:20.907Z","Website hack","https:\u002F\u002Fwww.linuxuprising.com\u002F2018\u002F06\u002Flinuxforumsorg-hack-exposes-276000-user.html",[15,17,18],"https:\u002F\u002Fweb.archive.org\u002Fweb\u002F20180502093437\u002Fhttp:\u002F\u002Fwww.linuxforums.org\u002Fforum","https:\u002F\u002Flinuxforums.org\u002F",275785,"known",null,"unknown","High",[25,26,27,28],"Email addresses","IP addresses","Passwords","Usernames","\u003Cp>The Linux Forums data breach is a verified security incident affecting the Linux help and support forum at the domain linuxforums.org on May 1, 2018. Records show that data including usernames, IP addresses, and password hashes along with the email addresses of 275,785 unique accounts were exposed. In the technical context of the incident, the forum software running on an old version of vBulletin stands out. The exposed passwords are not in plain text; they are password hashes stored in salted MD5 format. This distinction is important, but since MD5-based protection is weak against modern attack capabilities, old or reused passwords still pose a serious risk of account takeover. Because Linux community forums have been used for many years with the same usernames, this breach may affect not only forum accounts but also other technical community accounts opened with the same email and username.\u003C\u002Fp>\n\u003Ch2>Leaking Data Types and Risks\u003C\u002Fh2>\n\u003Cp>The verified data fields are email addresses, IP addresses, usernames, and password hashes. When an email address and username are present together, the risk of matching the person's identities used on other technical forums, open-source project areas, bug tracking systems, or social platforms increases. IP addresses can provide clues about the user's connection history, approximate region, or internet service provider. Even if the password field is not in plain text, being protected with salted MD5 is not considered a strong safeguard; this method is behind current standards against rapid trial attacks. Attackers can guess weak, short, or dictionary-based passwords through offline attempts. If the same password is reused in email, cloud, code hosting, forum, or server management panels, the risk can extend far beyond the forum account.\u003C\u002Fp>\n\u003Ch2>Verified Scope and Boundaries\u003C\u002Fh2>\n\u003Cp>This record is limited to Linux Forums forum membership data. The incident does not mean that the Linux kernel, Linux distributions, package repositories, open-source project code, or users' Linux servers were directly compromised. The verified fields are email, username, IP address, and password hash; phone number, physical address, payment card, official ID number, private message, or financial data are not among the verified fields for this record. The number 275,785 represents the count of unique affected accounts. Some secondary sources may show the rounded figure of 276 thousand; the number used here is the verified unique account value. Archived records accessible to the site during the incident period and independent technical reports support that the forum carried risks associated with its old vBulletin version. The current site status could not be additionally verified since the live domain did not respond from the production environment.\u003C\u002Fp>\n\u003Ch2>User Groups at Risk\u003C\u002Fh2>\n\u003Cp>The highest risk occurs for people who use the password from their Linux Forums account on other technical services as well. The same username in Linux and open source communities can be maintained for years on Git hosting services, package forums, distribution support areas, bug tracking systems, and IRC or chat accounts. This makes it easier for attackers to derive a broad online identity profile from a single forum registration. System administrators, developers, students, open source contributors, and active users in Linux support forums should be especially careful. If the email address is also a work account, targeted phishing may be attempted using messages that appear to be fake security alerts, package update notifications, or from community moderators.The inclusion of IP addresses can help the attacker craft a more convincing message based on the user's region or service provider.\u003C\u002Fp>\n\u003Ch2>Urgent Measures to Be Taken\u003C\u002Fh2>\n\u003Cp>If the password used in the Linux Forums account is repeated on another account, it should be changed immediately. Priority should be given to email accounts, code hosting services, server management panels, cloud accounts, Linux distribution forums, and package repository accounts. A unique, long, and hard-to-guess password should be used for each account; two-factor authentication should be enabled wherever possible. Unknown sessions should be closed after changing the password, and account recovery emails should be checked. Old forum accounts created with the same username should also be reviewed. Links appearing in email inboxes that seem related to Linux support, security patches, package updates, or forum account alerts should be approached with caution. If a link directs to a login page, the address should be checked manually, and the password should only be entered on the official service.\u003C\u002Fp>\n\u003Ch2>Long-Term Security Strategies\u003C\u002Fh2>\n\u003Cp>This incident shows that membership data stored in old forum software can pose a risk even years later. In the long term, password managers should be used for technical community accounts, and each forum, project space, code repository, and email account should be protected with a separate password. Old forum accounts should not be forgotten; unused accounts should be closed or at least switched to a unique password. Keeping the same username everywhere can be practical for technical reputation, but it increases the risk of identity matching. Especially system administrators and developers should reduce password, email, and username reuse between personal forum accounts and work accounts. Permanent traces such as IP addresses and emails cannot be reclaimed once circulated; therefore, two-factor authentication, session tracking, and security notifications should always be kept active on accounts.\u003C\u002Fp>\n\u003Ch2>Record Control and User Action\u003C\u002Fh2>\n\u003Cp>The presence of a match in this record indicates that your Linux Forums account information, including the email address, forum username, IP address, and password hash data, may have circulated. This does not mean that the password was visible in plain text; however, since salted MD5 protection is an old method, password reuse should be considered risky. The first action is to separate all accounts that use the same or similar passwords. Then, email account security, code repository accounts, cloud services, and other Linux community accounts should be checked. Even if there is no match, old forum passwords should be reviewed, because technical users may keep the same username and similar password patterns for years.The most correct approach is to make forum passwords unique, use two-factor authentication, and carefully examine unexpected login or password reset messages from technical communities.\u003C\u002Fp>","","Linux Forums Data Breach (275.8 Thousand Reported Records)","Linux Forums Data Breach. 275.8 Thousand reported records were reported. Reported data: Email addresses, IP addresses, Passwords. Review the scope, risks, and…","\u002Fuploads\u002Flogo\u002Flinuxforums_org.webp",false,{"name":36,"sector":37,"country":38,"website":9,"websiteArchiveUrl":30,"websiteStatus":30,"websiteCheckedAt":21},"Linux Forums","Technology","United States"]