[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fkp0uj0tel09o":3},{"success":4,"breach":5},true,{"_id":6,"name":7,"title":8,"slug":9,"domain":10,"breachDate":11,"addedDate":12,"modifiedDate":12,"contentUpdatedAt":13,"source":14,"sourceUrl":15,"sourceUrls":16,"pwnCount":17,"affectedCount":17,"affectedCountStatus":18,"affectedCountLowerBound":19,"affectedCountUnit":20,"hasEnglishDescription":4,"severity":21,"dataClasses":22,"description":30,"seoTitle":15,"seoTitleEn":31,"seoDescription":15,"seoDescriptionEn":32,"logoUrl":33,"isVerified":4,"isSensitive":4,"isSpamList":34,"isMalware":34,"company":35},"68e3266eda11adda488253b9","kodi-foundation","The Kodi Foundation Data Breach","the-kodi-foundation","kodi.tv","2023-02-16T00:00:00.000Z","2023-04-13T05:01:41.000Z","2026-07-18T23:59:21.058Z","Third party breach","",[],400635,"known",null,"unknown","High",[23,24,25,26,27,28,29],"Browser user agent details","Dates of birth","Email addresses","IP addresses","Passwords","Private messages","Usernames","\u003Cp>The Kodi Foundation data breach is a security incident recorded in February 2023 that affected approximately 401,000 accounts. In the incident related to the Kodi forum, forum account and user data were exposed. This content has been prepared to clearly help users understand which data fields are at risk and which security measures should be prioritized.\u003C\u002Fp>\u003Cp>The presence of private message, IP address, date of birth, and password fields together in the open-source media software community increases privacy and account security risks. Only verifiable data classes have been used in the text; unverified additional claims, different events, or similarly named services have not been combined under this record. This way, the explanation remains both useful to the user and a non-misleading assessment.\u003C\u002Fp>\u003Ch2>Leaking Data Types and Risks\u003C\u002Fh2>\u003Cp>The types of data listed in this incident are as follows: browser user agent information, birth dates, email addresses, IP addresses, passwords, private messages, and usernames. Private message and IP information can link the username to a real person or device behavior. Connecting multiple fields to the same user can make attackers' attempts at fake notifications, account recovery, social engineering, or identity correlation more convincing.\u003C\u002Fp>\u003Cp>It is understood that passwords are associated with MyBB salted hash values; even with a strong storage method, the risk of password reuse persists. If there are fields such as password, password hint, private message, official ID, financial information, location, or profile photo, the risk is not limited to just email spam. Even in records without passwords, phone, address, IP, date of birth, or social profile information can be used in targeted attacks.\u003C\u002Fp>\u003Ch2>Verified Scope and Boundaries\u003C\u002Fh2>\u003Cp>The record covers approximately 401,000 forum accounts associated with the domain kodi.tv. The incident is in the verified record class. The scope has been written by separately checking the number of accounts, domain, country, sector, and data classes. Data types not listed have not been shown as if they existed for the user.\u003C\u002Fp>\u003Cp>The sector has been corrected as open-source media software and forum community, not retail. In some cases, the company's response appears in different contexts such as a third-party service, forum account, newsletter list, or user profile. These records have been separated individually, not duplicated, and the actual service context of the incident has been preserved.\u003C\u002Fp>\u003Ch2>User Groups at Risk\u003C\u002Fh2>\u003Cp>Kodi forum users, people who use the same username in other open-source communities, and accounts with private message content are at risk. The main risk for these users is that leaked domains can be matched with information used on other platforms. If the same email, username, phone number, IP, address, or password is repeated across different accounts, attackers can exploit these common identifiers.\u003C\u002Fp>\u003Cp>The forum context can be used in phishing attempts themed around fake plugins, support, account verification, or private messages. Different contexts such as forums, games, recipes, accommodation, energy, event tickets, newsletters, social media, and finance generate different risks. The user should consider not only the data fields but also which service these fields are associated with.\u003C\u002Fp>\u003Ch2>Urgent Measures to Be Taken\u003C\u002Fh2>\u003Cp>Affected users should change their forum passwords and any accounts where the same password is repeated, and check whether they have shared sensitive information in private messages. If a password or password hint has been listed, users should change it on all accounts where they use the same or similar password, use a unique password, and enable multi-factor authentication wherever possible. Email account security should also be checked.\u003C\u002Fp>\u003Cp>Users should check account recovery options, session history, forwarding rules, and suspicious notifications in records containing phone, address, location, date of birth, private message, social profile, or financial information. Individuals with corporate or publicly accessible profiles should also consider the risk of targeted messages and reputation.\u003C\u002Fp>\u003Ch2>Long-Term Security Strategies\u003C\u002Fh2>\u003Cp>Old accounts should be closed in community forums, personal data should not be stored in private messages, and a unique password should be used. In the long term, a password manager, unique passwords, multi-factor authentication, closing old accounts, and reducing unnecessary profile information are the basic defense. Since permanent personal data cannot be changed, user behavior and account settings should be strengthened.\u003C\u002Fp>\u003Cp>For institutions, these events show that backup file accesses, forum account permissions, newsletter subscription data, customer data retention periods, and notification processes need to be regularly audited. For users, not repeating the same identity information across different services and verifying unexpected messages through a second channel provides lasting protection.\u003C\u002Fp>\u003Ch2>Record Control and User Action\u003C\u002Fh2>\u003Cp>If the user matches this record, they should also check other forums where they use the same username alongside their Kodi forum account. If a match is seen, the user should first read which data fields are listed and then prioritize the steps accordingly. If there is a password, password change should be prioritized; if there is financial data, account monitoring; if there are private messages or social profiles, privacy control; if there is a location, physical security assessment should be prioritized.\u003C\u002Fp>\u003Cp>Final assessment: This record is a sensitive forum data incident because it contains private messages, IP address, date of birth, and password fields. The user should compare this record with their account history; they should individually check the services where they used the same email, phone number, username, address, or password. Suspicious searches, emails, messages, or account recovery notifications should be considered higher risk after the incident.\u003C\u002Fp>","The Kodi Foundation Data Breach (400.6 Thousand Reported Records)","The Kodi Foundation Data Breach. 400.6 Thousand reported records were reported. Reported data: Browser user agent details, Dates of birth, Email addresses…","\u002Fuploads\u002Flogo\u002Fkodi_tv.webp",false,{"name":36,"sector":37,"country":38,"website":10,"websiteArchiveUrl":15,"websiteStatus":15,"websiteCheckedAt":19},"The Kodi Foundation","Open Source Media Software \u002F Forum","Global"]