The Candid Board Data Breach (2015): What Was Exposed & What To Do
SourceBreach data provided in part by Have I Been Pwned, used under CC BY 4.0.
The The Candid Board Data Breach (2015) (reported September 3, 2015) exposed Dates of birth, Email addresses, Geographic locations and IP addresses belonging to roughly 178K people. If you have an account with them, your information may now be circulating on the open web and with data brokers. Here’s exactly what happened, how to check if you were affected, and what to do next.
What happened
The breach occurred at The Candid Board, a site described as a non-consensual voyeurism forum. Attackers compromised the vBulletin installation and obtained account data for more than 178,000 users. The exposed material included email addresses, IP addresses, dates of birth, usernames, geographic locations, website activity, and passwords that had been salted and hashed with MD5. No further details on the intrusion method, exact timing of access, or subsequent use of the data have been publicly confirmed.
How a breach like this happens
Forum platforms such as vBulletin have historically been targeted through unpatched software vulnerabilities, weak administrative credentials, or compromised third-party plugins. Once initial access is obtained, attackers can extract database tables containing user records. Passwords stored with older hashing methods like unsalted or weakly salted MD5 are more susceptible to offline cracking than modern algorithms. Geographic locations and IP addresses are often logged automatically by forum software for moderation purposes, increasing the volume of data available if the database is reached.
Who is The Candid Board?
The Candid Board operated as an online forum focused on non-consensual voyeurism content. Organizations in this sector typically collect registration details to manage accounts and moderation, including contact information, device identifiers, and activity logs. A breach at such a site is consequential because the combination of personal identifiers and account credentials can be repurposed across unrelated services where users have reused passwords.
What data was at risk
- Dates of birth
- Email addresses
- Geographic locations
- IP addresses
- Passwords (salted MD5)
- Usernames
- Website activity
Why it matters
Exposed email addresses and usernames can facilitate targeted phishing or account takeover attempts on other platforms. Hashed passwords, even when salted, may be cracked over time if the hashing method is outdated, allowing reuse against additional sites. IP addresses and dates of birth add to the pool of information that can support identity verification fraud or more precise social-engineering attacks. For the organization, the incident highlighted the risks of running legacy forum software without current security controls.
If your data was in this breach
Change passwords on any accounts that reuse the exposed credentials, beginning with email and financial services. Enable multi-factor authentication wherever available. Monitor for unusual login attempts and consider using a password manager to generate unique credentials. Readers can run a free exposure scan of their email address against known breach datasets to determine whether their information appears in this or other documented incidents.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
Trillian Data Breach (2015)QuinStreet Data Breach (2015)Aternos Data Breach (2015)DaniWeb Data Breach (2015)Latest breaches
Read GalaxyWarden’s full analysis of the The Candid Board Data Breach (2015) →
Verified breach. Breach data provided in part by Have I Been Pwned, used under CC BY 4.0.
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.