Skip to content

phpBB

Disclosed Feb 5, 200917 years ago400,000 affectedUnverified

Attacker takes phpBB.com user database of 400,000 via unpatched PHPlist bug

An attacker exploited an unpatched bug in the third party PHPlist email application to gain full access to phpBB.com's database of names, emails, addresses and hashed passwords for its entire user base, and the site was taken offline.

What is known

People affected400,000 (as reported by the organization)
DisclosedFeb 5, 2009
AttackHacking
Data exposedNames, Emails, Addresses, Passwords
SectorTech · US
StatusUnverified: not yet confirmed by an official notice, a filing or the organization

Sources

Notices filed

WhereFiledPeople
ResearchtotalFeb 5, 2009400,000
History of this record
  • 2026-09-25 · added · seed source

First seen 2026-09-25 (Research). Record counts are as reported. Not legal advice.

Everything about phpBB

New breaches by email

Wednesdays, only in weeks with newly disclosed breaches, the largest first.

Double opt-in. Unsubscribe any time.