Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

A database table containing BreachForums user records became public in January 2026. BleepingComputer reported 323,988 records; Okta Threat Intelligence later described nearly 324,000 rows in its analysis. The reported fields included nicknames, email addresses, IP-address fields and hashed passwords—not plaintext passwords. The figures count records, not confirmed unique people or proven offenders.

What information was exposed?

Okta Threat Intelligence says the leaked table included nicknames, hashed passwords, email addresses, registration IP fields and last-visit IP fields. A password hash is a transformed representation of a password, not the original plaintext password. The cited reporting does not establish that the hashes were cracked.

Email entries also need caution: Okta says BreachForums did not verify email addresses, and some entries were invalid, missing or placeholder-like. A listed address therefore does not prove that a working mailbox belonged to the registrant.

How many accounts were in the leak?

BleepingComputer reported 323,988 user records. In its later analysis, Okta described 323,986 rows in its dataset and referred to nearly 324,000 database rows. The small difference reflects the two sources’ reported counts; neither number should be read as a tally of identified, unique individuals.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

When did the BreachForums data leak happen?

Public reporting about the exposed table appeared on January 10, 2026. That is distinct from the origin date claimed for the data: BleepingComputer quoted a forum administrator saying the users table came from an older leak dating to August 2025.

The administrator said that, during a restoration, the users table and forum PGP key were temporarily kept in an unsecured folder. That is the administrator’s explanation as relayed by BleepingComputer, not an independently established forensic conclusion. The reviewed reporting does not reliably identify who published the January 2026 archive or establish a compromise of the forum’s underlying server.

Do the IP addresses identify the people behind the accounts?

No. An IP field alone does not establish a person’s real-world identity or prove criminal activity. In its analysis, Okta reported that 235,208 rows had 127.0.0.9 in the cited registration or last-IP fields, while more than 88,700 last-IP values differed from that address. These are Okta’s dataset observations, not counts of confirmed identities. Okta also said about 75% of the BreachForums IPs it considered were not publicly routable and that it could enrich more than 35,000 IPs.

Okta cautioned that an IP associated with the forum does not necessarily belong to a threat actor: “law enforcement and cyber threat intelligence (CTI) researchers may use the same services in order to blend in.” Legitimate investigators and researchers used the forum, so a record cannot by itself establish who controlled an account or what that person did.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Does a BreachForums account prove someone was a hacker?

No. The leak does not establish that every row represents a distinct person, that every registrant committed a crime, or that the person named by an email or IP field controlled the account. The FBI describes BreachForums and RaidForums as criminal hacking forums and says it is investigating them, but its reporting portal does not confirm this particular 2026 leak or prove wrongdoing by any individual account holder. The FBI/IC3 reporting portal invites victims and people with relevant information to contact investigators.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What should you do if you reused a password?

If you used the same password on a legitimate service as on BreachForums, change it on that service. Use a unique password for each account and enable multifactor authentication where available. The reported exposure of hashed passwords is not evidence that those hashes were cracked, and the cited sources do not offer a way to determine whether a specific person or service is represented in the leak.

Sources and incident context

  • BleepingComputer reported the January 10, 2026 disclosure, the 323,988-record figure and the administrator’s account of an older backup.
  • Okta Threat Intelligence, in an analysis published March 29, 2026, described the dataset fields, its row count and its IP and email limitations.
  • FBI/IC3 provides the official reporting portal and historical forum context; it does not itself verify the specific 2026 leak.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.