Benchmark Data Breach (2019): What Was Exposed & What To Do
SourceBreach data provided in part by Have I Been Pwned, used under CC BY 4.0.
The Benchmark Data Breach (2019) (reported November 1, 2019) exposed Email addresses, IP addresses, Passwords and Usernames belonging to roughly 93K people. If you have an account with them, your information may now be circulating on the open web and with data brokers. Here’s exactly what happened, how to check if you were affected, and what to do next.
Inside the incident
The breach was reported on 1 November 2019. It affected 93,000 customer records from the Benchmark forum. The data types listed as exposed were email addresses, IP addresses, usernames, and passwords stored as salted MD5 hashes. The forum administrator attributed the incident to the forum previously running on an outdated vBulletin instance. No further details on the timing of the intrusion, the method of access, or the total number of files involved have been disclosed.
How a breach like this happens
Incidents involving older forum software often begin with the exploitation of known vulnerabilities in unpatched installations. Attackers scan for publicly documented weaknesses in platforms such as vBulletin and use them to gain access to the underlying database. Once inside, they can extract user tables that contain login credentials and associated metadata. The use of salted MD5 hashes, while stronger than unsalted hashes, still leaves passwords open to offline cracking attempts if the salt values and hash lists are obtained.
Benchmark and its sector
Benchmark operates as a technology news website in Serbia and maintains a forum for reader discussion. Organisations in this sector routinely collect usernames, email addresses, and IP logs to manage accounts and moderate content. A breach at such a site is consequential because forum users frequently reuse credentials across multiple services, and the combination of email addresses with password hashes can facilitate further account access elsewhere.
What data was at risk
The breach record identifies email addresses, usernames, IP addresses, and passwords stored as salted MD5 hashes as the data types exposed. No other categories of information, such as full names, payment details, or private messages, are named in the available reporting. The precise contents of the dataset beyond these fields remain unconfirmed.
The real-world impact
Individuals whose records were exposed face the possibility that their email addresses and password hashes could be used in credential-stuffing attacks against other sites. IP addresses may allow correlation with other online activity. For the organisation, the incident highlights the long-term risk of retaining user data on unsupported software versions, which can extend the window during which records remain accessible after an intrusion.
Were you affected?
Users who registered on the Benchmark forum before November 2019 should treat any password associated with that account as potentially compromised and change it on any other service where the same credentials were used. Checking whether an email address appears in known breach datasets provides one practical starting point for assessing exposure. Readers can run a free exposure scan of their email address to review whether their information has surfaced in publicly documented breach data.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
Sonicbids Data Breach (2019)Go Ninja Data Breach (2019)GameSprite Data Breach (2019)Avvo Data Breach (2019)Latest breaches
Read GalaxyWarden’s full analysis of the Benchmark Data Breach (2019) →
Verified breach. Breach data provided in part by Have I Been Pwned, used under CC BY 4.0.
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.