[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fyalq8faa24ml":3},{"success":4,"breach":5},true,{"_id":6,"name":7,"title":8,"slug":7,"domain":9,"breachDate":10,"addedDate":11,"publishedAt":12,"modifiedDate":13,"contentUpdatedAt":14,"source":15,"sourceUrl":16,"sourceUrls":17,"pwnCount":18,"affectedCount":18,"affectedCountStatus":19,"affectedCountLowerBound":12,"affectedCountUnit":20,"hasEnglishDescription":4,"contentLocale":21,"availableLocales":22,"translations":24,"severity":27,"dataClasses":28,"description":33,"seoTitle":34,"seoDescription":35,"logoUrl":36,"isVerified":4,"isSensitive":4,"isSpamList":37,"isMalware":37,"company":38},"6a452308a20f867c8ba8e717","the-botting-network","The Botting Network Data Breach","thebotnet.com","2012-08-12T00:00:00.000Z","2025-12-18T01:33:47.000Z",null,"2026-07-07T10:14:39.762Z","2026-07-19T00:02:36.179Z","Third party breach","",[],96320,"known","unknown","en",[21,23],"tr",{"en":25,"tr":26},{"slug":7},{"slug":7},"Medium",[29,30,31,32],"Dates of birth","Email addresses","Passwords","Usernames","\u003Cp>The Botting Network data breach was recorded in August 2012 with the exposure of old vBulletin-based user records associated with botting and the forum community. The dataset, which contained approximately 96,000 unique email addresses, included usernames, birth dates, and password hashes stored in salted MD5 format. Even though the forum is no longer active, the presence of email, username, birth date, and password fields together still poses a risk to account security.\u003C\u002Fp>\u003Cp>The types of data listed in this record are the fields Dates of birth, Email addresses, Passwords, and Usernames. Salted MD5 is not considered strong according to modern password storage standards. Therefore, affected users need to check whether they have reused the password they used on their The Botting Network account on other email, forum, game, developer, or payment accounts.\u003C\u002Fp>\u003Ch2>Leaking Data Types and Risks\u003C\u002Fh2>\u003Cp>The biggest mistake in old forum violations is assuming that the incident is no longer important because it is old. Users may have repeated the same password pattern across different accounts over the years. An attacker might try to crack old salted MD5 hashes or attempt similar password patterns on other services. Therefore, not only the same password but also similar word and number combinations need to be changed.\u003C\u002Fp>\u003Cp>The date of birth field increases the risk of identity matching when combined with username and email. Some older forums and account recovery processes may use the date of birth for verification purposes. Users affected should switch to alternative verification methods if they use their date of birth as a security question or support verification on other services.\u003C\u002Fp>\u003Ch2>Verified Scope and Boundaries\u003C\u002Fh2>\u003Cp>The context of The Botting Network can also pose a separate reputational risk. Associating a user with such a forum does not, by itself, prove their level of activity or purpose; however, the forum name can be used in social engineering or threat messages. The user can be contacted regarding their old account, forum history, membership proof, or data deletion request. In such messages, no payment should be made, and no additional information should be shared.\u003C\u002Fp>\u003Cp>The username field may have been reused across different forums, gaming accounts, messaging channels, and social platforms. If the same nickname is linked to real identity or contact information on other accounts, the old forum record can be connected to a broader digital profile. Affected individuals should reduce unnecessary personal information on public profiles.\u003C\u002Fp>\u003Ch2>User Groups at Risk\u003C\u002Fh2>\u003Cp>From the perspective of institutions, this incident shows the risk of the data life cycle of closed forums and old community systems. Password hashes and profile fields in unused systems can remain in circulation for years. In old vBulletin-based communities, password storage, backup archives, and user deletion processes require special attention.\u003C\u002Fp>\u003Cp>Affected users should change their old passwords to unique and strong passwords, enable multi-factor authentication on their main email account, and review other accounts using the same username. Although this record is old, it still poses a meaningful risk to current account security due to the birth date, username, and password hashes.\u003C\u002Fp>\u003Ch2>Urgent Measures to Be Taken\u003C\u002Fh2>\u003Cp>This record also indicates that the date of birth information used in old community accounts could be matched with other accounts in the future. If a user used the same nickname in games, forums, or software communities around 2012, this old record could be linked to current profiles. The date of birth can also strengthen this match. Therefore, old nicknames and public profiles should be reviewed.\u003C\u002Fp>\u003Cp>Due to the context of botting, users may be targeted with fake warnings, old membership, account closure, or data deletion messages. Such messages appear more realistic if they include the user's past forum name. Users should not respond hastily to messages that pressure them about past behavior, should not make payments, and should not share additional personal information.\u003C\u002Fp>\u003Ch2>Long-Term Security Strategies\u003C\u002Fh2>\u003Cp>For institutions, this incident shows that old forum backups and user tables can pose a risk for years. When decommissioning old systems containing user data, simply taking the site offline is not enough; backups, password hashes, and profile fields must also be securely cleaned.\u003C\u002Fp>\u003Cp>Affected individuals should check the login history, recovery addresses, and connected applications on their main email accounts. Even if the old forum breach does not directly provide access to the current account, it can pave the way for new attacks due to password reuse and the use of birth dates.\u003C\u002Fp>\u003Ch2>Record Control and User Action\u003C\u002Fh2>\u003Cp>If this record matches your email address, check your accounts by considering the listed data types one by one. Even if the incident is old, email, password, phone, address, or identity context can be combined with other data sets and later used in targeted fraud.\u003C\u002Fp>\u003Cp>The priority is to change accounts that use the same password, enable two-step verification on critical accounts, log out of unexpected sessions, and use the known login page instead of links to avoid fake notifications. Even if there is no password in the record, the email and profile fields may be sufficient for phishing.\u003C\u002Fp>","The Botting Network Data Breach (96.3 Thousand Reported Records)","The Botting Network Data Breach. 96.3 Thousand reported records are reported. Reported data: Dates of birth, Email addresses, Passwords. Review the scope…","\u002Fuploads\u002Flogo\u002Fthebotnet_com.webp",false,{"name":39,"sector":40,"country":16,"website":9,"websiteArchiveUrl":16,"websiteStatus":16,"websiteCheckedAt":12},"The Botting Network","Forum"]