Menu
Browse

Cyber Incident Victim: Comodo Group, Inc.

Date:

Sep 2019

Location:

United States of America

Summary

A cybersecurity breach impacted Comodo Forums after attackers exploited a vulnerability in the vBulletin software powering the platform, leading to unauthorized database access. The incident compromised account data belonging to over 170,000 users—representing more than half of the forum's user base—with the stolen information subsequently traded online. The organization acknowledged the intrusion through a security notice confirming potential exposure of user records.

CIA Posture Motives Tactics, Techniques & Procedures
Available to members 3 motives 1 technique
Threat Actors Type Location
0 actors Available to members Available to members

Description

On or around September 29, 2019, an unauthorized actor breached the Comodo Forums by exploiting a vulnerability in the vBulletin software that powered the platform. This intrusion resulted in the theft of account data belonging to over 170,000 users, representing more than half of the forum's total user base. The stolen information subsequently appeared for sale on online trading platforms, exposing affected individuals to potential credential misuse and secondary attacks. Comodo publicly acknowledged the incident on October 1, 2019, through a security notice confirming that an intruder had potentially accessed the forum's database. While the company did not specify the exact timeline of vulnerability exploitation or data exfiltration, the breach's discovery coincided with broader awareness of security flaws in vBulletin systems during that period.

Cyber Incident Image

Comodo's response centered on notifying users about the potential compromise of their forum account credentials and personal information associated with their profiles. The company did not disclose whether additional remediation steps were taken beyond the security notice, such as forced password resets or detailed forensic analysis of the attack vector. The incident directly impacted the confidentiality of user data stored within the forum's database, though the extent of financial or operational damage to Comodo's broader infrastructure remained unspecified in available disclosures. The public exposure of stolen credentials increased risks for forum users who reused passwords across multiple services, creating potential secondary compromise scenarios beyond Comodo's systems. The breach underscored persistent security challenges associated with third-party forum software platforms widely used across the technology sector.

Sources
Sources available to members
1 source