LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

Recent Breaches › Benchmark Data Breach (2019)

HIGH severityConfirmedHow we verify

Benchmark Data Breach (2019): What Was Exposed & What To Do

RBRecent Breaches Breach Intelligence·November 1, 2019

SourceBreach data provided in part by Have I Been Pwned, used under CC BY 4.0.

Benchmark Data Breach (2019)

Reported November 1, 2019. Approximately 93K people affected.

HIGH
Severity
93K
People affected
4
Data types exposed
November 1, 2019
Disclosed
ShareXLinkedInFacebookRedditWhatsAppTelegram

The Benchmark Data Breach (2019) (reported November 1, 2019) exposed Email addresses, IP addresses, Passwords and Usernames belonging to roughly 93K people. If you have an account with them, your information may now be circulating on the open web and with data brokers. Here’s exactly what happened, how to check if you were affected, and what to do next.

Severity & verification
HIGH severityConfirmed
Account credentials exposed.
Corroborated by an official disclosure or a verified breach feed.
Was your email in the Benchmark Data Breach (2019) breach?
93K accounts were exposed here. See if yours is one — and every other breach it’s in. 15-sec check, no card.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

In November 2019, a breach of the forum operated by the Serbian technology news website Benchmark exposed records for 93,000 users. The exposed data included email addresses, usernames, IP addresses, and passwords stored as salted MD5 hashes. A forum administrator later stated that the incident stemmed from the forum running on an outdated version of vBulletin software. The exposure of account credentials and contact details from a long-running online forum raises direct questions for users about reuse of passwords and the persistence of old account information.

Inside the incident

The breach was reported on 1 November 2019. It affected 93,000 customer records from the Benchmark forum. The data types listed as exposed were email addresses, IP addresses, usernames, and passwords stored as salted MD5 hashes. The forum administrator attributed the incident to the forum previously running on an outdated vBulletin instance. No further details on the timing of the intrusion, the method of access, or the total number of files involved have been disclosed.

How a breach like this happens

Incidents involving older forum software often begin with the exploitation of known vulnerabilities in unpatched installations. Attackers scan for publicly documented weaknesses in platforms such as vBulletin and use them to gain access to the underlying database. Once inside, they can extract user tables that contain login credentials and associated metadata. The use of salted MD5 hashes, while stronger than unsalted hashes, still leaves passwords open to offline cracking attempts if the salt values and hash lists are obtained.

Benchmark and its sector

Benchmark operates as a technology news website in Serbia and maintains a forum for reader discussion. Organisations in this sector routinely collect usernames, email addresses, and IP logs to manage accounts and moderate content. A breach at such a site is consequential because forum users frequently reuse credentials across multiple services, and the combination of email addresses with password hashes can facilitate further account access elsewhere.

What data was at risk

The breach record identifies email addresses, usernames, IP addresses, and passwords stored as salted MD5 hashes as the data types exposed. No other categories of information, such as full names, payment details, or private messages, are named in the available reporting. The precise contents of the dataset beyond these fields remain unconfirmed.

The real-world impact

Individuals whose records were exposed face the possibility that their email addresses and password hashes could be used in credential-stuffing attacks against other sites. IP addresses may allow correlation with other online activity. For the organisation, the incident highlights the long-term risk of retaining user data on unsupported software versions, which can extend the window during which records remain accessible after an intrusion.

Were you affected?

Users who registered on the Benchmark forum before November 2019 should treat any password associated with that account as potentially compromised and change it on any other service where the same credentials were used. Checking whether an email address appears in known breach datasets provides one practical starting point for assessing exposure. Readers can run a free exposure scan of their email address to review whether their information has surfaced in publicly documented breach data.

AICompiled with AI assistance from public sources and published under our editorial standards.

Editorial & sourcing policy
Recent Breaches is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data, and we do not hold the data claimed in leak-site listings. Incidents are compiled from publicly accessible sources and threat-intelligence platforms and are reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — write to support@galaxywarden.com or press@recentbreaches.com.
Check if you’re exposed →

How this breach connects

Company

Method

CompanyBenchmark security record
74/100
DoxxScan™ · Moderate doxx risk
B- 78Above-average record

1 reported incident on record.

See Benchmark’s full breach history →

More recent breaches

Sonicbids Data Breach (2019)December 30, 2019Go Ninja Data Breach (2019)December 17, 2019GameSprite Data Breach (2019)December 17, 2019Avvo Data Breach (2019)December 17, 2019

Latest breaches

Read GalaxyWarden’s full analysis of the Benchmark Data Breach (2019) →

Verified breach. Breach data provided in part by Have I Been Pwned, used under CC BY 4.0.

Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.

Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.

ShareXLinkedInFacebookRedditWhatsAppTelegram