


This requires actions from the team, and forum users: At the current time, we have found no evidence of unauthorised access to the underlying server that hosts the MyBB software.Īlthough MyBB stores passwords in an encrypted format we must assume all passwords are compromised. The nightly full backups that were downloaded expose all public forum posts, all team forum posts, all messages sent through the user-to-user messaging system, and user data including forum username, email address used for notifications, and an encrypted (hashed and salted) password generated by the MyBB (v1.8.27) software. The admin team have disabled the account used in the breach and have conducted an initial review of team infrastructure the team member had access to. The account owner has confirmed they did not access the admin console to perform these actions. It also downloaded existing nightly full-backups of the database. The account was used to create database backups which were then downloaded and deleted. MyBB admin logs show the account of a trusted but currently inactive member of the forum admin team was used to access the web-based MyBB admin console twice: on 16 February and again on 21 February. This post confirms that a breach has taken place.

In the last 24 hours we became aware of a dump of the Kodi user forum (MyBB) software being advertised for sale on internet forums. In addition, the Kodi wiki and paste sites are now back online. If you need help while we recover/rebuild the systems, you can find a read-only April snapshot of the forum on the Internet Archive here.
