LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

Recent Breaches › Boxee Data Breach (2014)

HIGH severityConfirmedHow we verify

Boxee Data Breach (2014): What Was Exposed & What To Do

RBRecent Breaches Breach Intelligence·March 29, 2014

SourceBreach data provided in part by Have I Been Pwned, used under CC BY 4.0.

Boxee Data Breach (2014)

Reported March 29, 2014. Approximately 158K people affected.

HIGH
Severity
158K
People affected
10
Data types exposed
March 29, 2014
Disclosed
ShareXLinkedInFacebookRedditWhatsAppTelegram

The Boxee Data Breach (2014) (reported March 29, 2014) exposed Dates of birth, Email addresses, Geographic locations and Historical passwords belonging to roughly 158K people. If you have an account with them, your information may now be circulating on the open web and with data brokers. Here’s exactly what happened, how to check if you were affected, and what to do next.

Severity & verification
HIGH severityConfirmed
Account credentials exposed.
Corroborated by an official disclosure or a verified breach feed.
Was your email in the Boxee Data Breach (2014) breach?
158K accounts were exposed here. See if yours is one — and every other breach it’s in. 15-sec check, no card.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

In March 2014, the online forums operated by home theatre software maker Boxee were compromised, resulting in the extraction and public posting of a copy of the associated vBulletin MySQL database. The incident affected records belonging to 158,000 users and was reported on 29 March 2014. Such events remain relevant today because user databases from smaller online communities continue to be targeted for the range of personal identifiers and credentials they often contain.

What happened

The compromise centred on Boxee's forums. Attackers obtained the full vBulletin MySQL database and posted it for download on the forum itself. The material included records spanning nearly 200 publicly exposed tables and covered password histories along with private messages. No further information on the precise date of intrusion, the scale of any additional files accessed, or the technical method employed has been disclosed in public reports of the incident.

How a breach like this happens

Forum platforms built on older web applications can be reached through unpatched software vulnerabilities or compromised administrative credentials. Once inside, an attacker may locate and copy the underlying database that stores user accounts, messages and configuration data. The copied material is sometimes reposted in the same location to demonstrate access or to distribute it further. These steps do not require advanced techniques when the target application has known weaknesses or when credentials are reused across systems.

Who is Boxee?

Boxee developed software that enabled users to organise and play media files on home theatre personal computers. Companies in this consumer software sector routinely operate discussion forums to support their products, and those forums collect the account details needed for registration and communication. A breach at such a service is consequential because the data held there can extend beyond simple login information to include personal identifiers and conversation histories that users may not expect to be copied or shared.

The information in question

Public reports of the incident list the following categories of information among the exposed records: dates of birth, email addresses, geographic locations, historical passwords, instant messenger identities, IP addresses, passwords and private messages. The exact contents of every table or the completeness of each category have not been independently verified beyond the initial description of the database dump.

Why it matters

Individuals whose details appeared in the database may face an elevated chance that their email addresses and passwords, including older versions, could be tested against other online services. Geographic locations and dates of birth can contribute to identity verification processes elsewhere, while private messages may reveal additional context about users' activities. For the organisation, the public posting of the database on its own forum can erode trust among remaining users and prompt reviews of how forum data is stored and protected.

If your data was in this breach

Begin by changing the password on any account that used the same credentials listed in the exposed material, and enable multi-factor authentication where available. Review recent account activity on services tied to the same email address. Individuals can also run a free exposure scan of their email address against known breach data sets to determine whether their information appears in additional records beyond this incident.

AICompiled with AI assistance from public sources and published under our editorial standards.

Editorial & sourcing policy
Recent Breaches is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data, and we do not hold the data claimed in leak-site listings. Incidents are compiled from publicly accessible sources and threat-intelligence platforms and are reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — write to support@galaxywarden.com or press@recentbreaches.com.
Check if you’re exposed →

How this breach connects

Company

Method

CompanyBoxee security record
74/100
DoxxScan™ · Moderate doxx risk
B- 78Above-average record

1 reported incident on record.

See Boxee’s full breach history →

More recent breaches

Team SoloMid Data Breach (2014)December 22, 2014Acne.org Data Breach (2014)November 25, 2014Malwarebytes Data Breach (2014)November 15, 2014Bot of Legends Data Breach (2014)November 13, 2014

Latest breaches

Read GalaxyWarden’s full analysis of the Boxee Data Breach (2014) →

Verified breach. Breach data provided in part by Have I Been Pwned, used under CC BY 4.0.

Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.

Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.

ShareXLinkedInFacebookRedditWhatsAppTelegram