OGUsers, a forum associated with account hijacking and SIM swapping activity, suffered separate data breaches in April 2021 and July 2022 that exposed user account information from hundreds of thousands of members. The 2021 incident affected 348,000 unique email addresses, while the 2022 breach exposed 529,000 unique email addresses, according to records added to Have I Been Pwned.
The stolen data included usernames, email addresses, IP addresses, and password hashes. In the 2021 breach, passwords were stored with either salted MD5 or Argon2, and the data was later offered for sale on a rival hacking forum. In the 2022 breach, passwords were stored as Argon2 hashes. The 2022 incident was identified as the fifth breach affecting OGUsers since December 2018, underscoring a repeated pattern of compromise at the forum.

See attribution, scope, and your downstream exposure.
3 events from the most recent confirmed update back to the earliest known activity.
In July 2022, OGUsers experienced another data breach, its fifth since December 2018. The exposed dataset included usernames, email addresses, IP addresses, and Argon2-hashed passwords, affecting 529,000 unique email addresses.
After the April 2021 breach, the stolen OGUsers data was offered for sale on a rival hacking forum. This sale involved the dataset from the 2021 incident.
In April 2021, the account hijacking and SIM swapping forum OGUsers experienced a data breach. The exposed data included usernames, email addresses, IP addresses, and passwords hashed with either salted MD5 or Argon2, affecting 348,000 unique email addresses.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See attribution, scope, and whether this vendor sits anywhere in your supply chain.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.