LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

Recent Breaches › The Candid Board Data Breach (2015)

HIGH severityConfirmedHow we verify

The Candid Board Data Breach (2015): What Was Exposed & What To Do

RBRecent Breaches Breach Intelligence·September 3, 2015

SourceBreach data provided in part by Have I Been Pwned, used under CC BY 4.0.

The Candid Board Data Breach (2015)

Reported September 3, 2015. Approximately 178K people affected.

HIGH
Severity
178K
People affected
7
Data types exposed
September 3, 2015
Disclosed
ShareXLinkedInFacebookRedditWhatsAppTelegram

The The Candid Board Data Breach (2015) (reported September 3, 2015) exposed Dates of birth, Email addresses, Geographic locations and IP addresses belonging to roughly 178K people. If you have an account with them, your information may now be circulating on the open web and with data brokers. Here’s exactly what happened, how to check if you were affected, and what to do next.

Severity & verification
HIGH severityConfirmed
Account credentials exposed.
Corroborated by an official disclosure or a verified breach feed.
Was your email in the The Candid Board Data Breach (2015) breach?
178K accounts were exposed here. See if yours is one — and every other breach it’s in. 15-sec check, no card.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

In September 2015, a data breach at The Candid Board exposed records associated with more than 178,000 accounts on the site’s vBulletin forum. The incident was reported on September 3, 2015, and involved the disclosure of email addresses, IP addresses, dates of birth, usernames, geographic locations, website activity, and salted passwords stored as MD5 hashes. Such incidents remain relevant today because data from older forum compromises continues to circulate in criminal markets and is reused in credential-stuffing campaigns against current services.

What happened

The breach occurred at The Candid Board, a site described as a non-consensual voyeurism forum. Attackers compromised the vBulletin installation and obtained account data for more than 178,000 users. The exposed material included email addresses, IP addresses, dates of birth, usernames, geographic locations, website activity, and passwords that had been salted and hashed with MD5. No further details on the intrusion method, exact timing of access, or subsequent use of the data have been publicly confirmed.

How a breach like this happens

Forum platforms such as vBulletin have historically been targeted through unpatched software vulnerabilities, weak administrative credentials, or compromised third-party plugins. Once initial access is obtained, attackers can extract database tables containing user records. Passwords stored with older hashing methods like unsalted or weakly salted MD5 are more susceptible to offline cracking than modern algorithms. Geographic locations and IP addresses are often logged automatically by forum software for moderation purposes, increasing the volume of data available if the database is reached.

Who is The Candid Board?

The Candid Board operated as an online forum focused on non-consensual voyeurism content. Organizations in this sector typically collect registration details to manage accounts and moderation, including contact information, device identifiers, and activity logs. A breach at such a site is consequential because the combination of personal identifiers and account credentials can be repurposed across unrelated services where users have reused passwords.

What data was at risk

Why it matters

Exposed email addresses and usernames can facilitate targeted phishing or account takeover attempts on other platforms. Hashed passwords, even when salted, may be cracked over time if the hashing method is outdated, allowing reuse against additional sites. IP addresses and dates of birth add to the pool of information that can support identity verification fraud or more precise social-engineering attacks. For the organization, the incident highlighted the risks of running legacy forum software without current security controls.

If your data was in this breach

Change passwords on any accounts that reuse the exposed credentials, beginning with email and financial services. Enable multi-factor authentication wherever available. Monitor for unusual login attempts and consider using a password manager to generate unique credentials. Readers can run a free exposure scan of their email address against known breach datasets to determine whether their information appears in this or other documented incidents.

AICompiled with AI assistance from public sources and published under our editorial standards.

Editorial & sourcing policy
Recent Breaches is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data, and we do not hold the data claimed in leak-site listings. Incidents are compiled from publicly accessible sources and threat-intelligence platforms and are reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — write to support@galaxywarden.com or press@recentbreaches.com.
Check if you’re exposed →

How this breach connects

Company

Method

CompanyThe Candid Board security record
74/100
DoxxScan™ · Moderate doxx risk
B- 78Above-average record

1 reported incident on record.

See The Candid Board’s full breach history →

More recent breaches

Trillian Data Breach (2015)December 27, 2015QuinStreet Data Breach (2015)December 14, 2015Aternos Data Breach (2015)December 6, 2015DaniWeb Data Breach (2015)December 1, 2015

Latest breaches

Read GalaxyWarden’s full analysis of the The Candid Board Data Breach (2015) →

Verified breach. Breach data provided in part by Have I Been Pwned, used under CC BY 4.0.

Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.

Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.

ShareXLinkedInFacebookRedditWhatsAppTelegram