phpBB
Disclosed Feb 5, 200917 years ago400,000 affectedUnverified
Attacker takes phpBB.com user database of 400,000 via unpatched PHPlist bug
An attacker exploited an unpatched bug in the third party PHPlist email application to gain full access to phpBB.com's database of names, emails, addresses and hashed passwords for its entire user base, and the site was taken offline.
What is known
| People affected | 400,000 (as reported by the organization) |
|---|---|
| Disclosed | Feb 5, 2009 |
| Attack | Hacking |
| Data exposed | Names, Emails, Addresses, Passwords |
| Sector | Tech · US |
| Status | Unverified: not yet confirmed by an official notice, a filing or the organization |
Sources
| Source | |
|---|---|
| Privacy Rights Clearinghouse: A Chronology of Data Breaches (archived February 2010)web.archive.org · News | News |
Notices filed
| Where | Filed | People |
|---|---|---|
| Researchtotal | Feb 5, 2009 | 400,000 |
History of this record
- 2026-09-25 · added · seed source
First seen 2026-09-25 (Research). Record counts are as reported. Not legal advice.