Menu
Browse

Cyber Incident Victim: dBforums

Date:

Jul 2016

Location:

United States of America

Summary

A cyberattack compromised multiple online forums including Web Hosting Talk, Mac Forums, and dBforums, resulting in the theft of approximately 1.4 million user records containing email addresses and passwords. The stolen credentials were cryptographically protected using salted MD5 hashes, a method considered vulnerable, with attackers reportedly cracking 60% of the passwords within hours. The breach originated from a compromise of parent company Penton's systems, and the stolen databases were subsequently offered for sale on a dark web marketplace. LeakedSource, a breach notification service, publicly disclosed the incident after validating the data's authenticity.

CIA Posture Motives Tactics, Techniques & Procedures
Available to members 1 motive 1 technique
Threat Actor Type Location
1 actor Available to members Available to members

Description

In July 2016, hackers breached the media company Penton and stole databases from multiple online forums, including Web Hosting Talk, Mac Forums, HotScripts, dBforums, and A Best Web. The intrusion occurred on July 4, 2016, compromising 1,442,602 user accounts containing email addresses, usernames, and passwords. The stolen data appeared for sale on the dark web marketplace The Real Deal by an individual using the alias "uid0," who listed the combined databases for 7.2 bitcoin (approximately $4,752 at the time). Security researchers from LeakedSource, a data breach monitoring service, independently verified the breach and disclosed it publicly on an unspecified Friday evening following the incident. Analysis confirmed the passwords were hashed using MD5 with salting, though LeakedSource reported cracking approximately 60% of the passwords within two hours due to MD5's cryptographic weaknesses. The attacker's methods for infiltrating Penton's systems were not detailed in available reports.

Cyber Incident Image

The incident exposed users across all five forums to credential-stuffing attacks and account takeovers, particularly given the prevalence of password reuse. LeakedSource's disclosure urged affected users to immediately change passwords on the compromised forums and any other platforms where they reused credentials. No statements from Penton or the individual forum operators regarding remediation efforts, forensic investigations, or user notifications were documented in the provided sources. The sale listing remained active on The Real Deal at the time of reporting, though uptake by buyers was unconfirmed. The breach highlighted systemic risks associated with outdated hashing algorithms and centralized database management for interconnected web properties under single corporate ownership.

Sources
Sources available to members
2 sources