Search TorWire

Find cybersecurity guides and research articles

Home > News > Cybersecurity > Hacker Claims Breach and Sells Alleged Qufu Marathon User Database

Hacker Claims Breach and Sells Alleged Qufu Marathon User Database

By: Jordan Vector Cybersecurity Expert

Last updated: July 21, 2026

Human Written
Hacker Claims Breach and Sells Alleged Qufu Marathon User Database
  • A hacker claimed to breach qufumarathon.com and allegedly exposed 69,082 user records alongside administrative backend logins.

  • The leaked database sample contains administrative usernames, hashed passwords, account settings, and personal user profile data.

  • Security experts urge online platforms to enforce multi-step login verification, update password hashing, and restrict administrative access.

An online attacker recently claimed responsibility for invading a popular Chinese marathon website. The hacker targeted the digital system behind qufumarathon.com to steal private records. The intruder claimed full control over the platform’s administrative backend.

The bad actor posted the announcement on an underground digital forum, sharing a free sample of the stolen database online. The leak allegedly exposes 69,082 individual user records and private account details. The stolen files include administrative usernames, profile data, and scrambled account passcodes.

Platform administrators oversee runner registrations and manage race events across the country. So, an administrative intrusion creates massive safety risks for everyone involved. Security researchers monitor these online disclosures to confirm whether the breach is real. Platform managers have not issued any public statements regarding the incident yet.

How the Hacker Broke into the Marathon Backend Database

The administrative backend acts as the control tower for the entire marathon platform. Managers use this central dashboard to update race schedules and view runner profiles. When a hacker breaches this backend control panel, standard safety barriers fail completely. 

Notably, administrative access allows intruders to change website files and view hidden database records. In this attack, the criminal claimed total control over these administrative controls. The bad actor also downloaded thousands of private profiles without triggering alarms.

The breached database has scrambled passcodes as protection, with compliance with the hashing technique. Usually, developers turn simple passwords into complex algorithms through hashing. However, weaker hashing methods facilitate the process of password cracking for hackers using computer scripts.

Hackers can automate the comparison of millions of commonly used words within a few seconds. Many people reuse passwords on different sites. Thus, when defrauders receive a database with passwords from one site, they can use this information to hack accounts on other sites as well.

According to security experts, fraudsters usually exaggerate their statements. Cybercriminals also use old documents to lure buyers on dark web markets. For this reason, specialists often try to verify posted documents to determine whether the combination of passwords is new or not. Technical staff can identify security gaps and lock down compromised accounts early. The same caution applies to other alleged database sales; a hacker has claimed to sell an Association.fr database without verification.

Why Administrative Breaches Threaten Platform Safety

Standard user breaches usually expose basic details like public comments or display names. Administrative account breaches give attackers master keys to the entire system. This means intruders can manipulate website software and upload malicious code silently. 

Also, bad actors can create fake administrative accounts to maintain long-term access. This persistent entry lets criminals watch daily visitor activity without leaving obvious clues. Administrative intrusions represent the most dangerous threat to online platforms.

Marathon platforms collect extensive personal details from thousands of active runners. Submissions by participants comprise comprehensive names alongside other private details including phone numbers, email addresses, and emergency contact listings. With this information, cybercriminals are able to gather private intelligence to create complete files and records of information about their victims. 

Criminals typically send fictitious yet convincing messages aimed at redirecting unsuspecting victims or tricking them into disclosing bank details. The information they obtained illegally is what they actively use in identity fraud schemes. Hence, the attacked companies will continually encounter security issues of spam messages or phone fraud. 

Tampering with event databases disrupts the real activities of the sports events and the organization of the races. Intruders can change the bib numbers of the runners or delete the registration lists of runners. They can also shut down payment portals during busy registration periods. 

Notably, athletic organizations suffer severe financial losses and lose public trust after breaches. So, protecting administrative account controls remains vital for preserving operational stability and brand reputation. Also, platform owners must implement continuous monitoring tools to spot unauthorized backend access.

Protective Steps to Secure Online Registration Systems

Website administrators must enforce strong passcode requirements across all staff accounts. System managers should demand complex passcodes that blend numbers, letters, and symbols. Consequently, developers must upgrade password storage systems using modern salt encryption methods. This technique adds random data to each passcode before scrambling it.

Strong mathematical protection stops automated cracking tools effectively. These tools cannot decode scrambled passcodes quickly. Therefore, proper encryption shields personal accounts even if database files leak online. Additionally, this protection keeps user information safe from prying eyes.

Organizations should mandate multi-step verification for all administrative account logins – this process requires a temporary phone code during sign-in. Some systems use a physical security token instead. Hence, extra login barriers stop unauthorized users from gaining entry. They work even if account passcodes leak on public forums. Moreover, these barriers add a crucial layer of defense.

Technical teams must restrict backend access to trusted company internet connections. Blocking unknown connection attempts stops overseas hackers effectively. Consequently, overseas attackers cannot reach administrative portals easily. Firewalls also block suspicious connection traffic before it touches internal databases. In fact, this prevents attacks before they even start.

Platform operators must run regular security scans to discover hidden software bugs. Automated testing tools spot outdated software scripts quickly. Therefore, developers can fix issues before cybercriminals exploit them. Updating backend software tools closes known entry doors used by digital intruders, and regular updates will keep the system resilient against new threats.

Companies must save isolated offline backup copies of all runner records. Businesses should isolate sensitive database files from public web servers. For instance, storing backups offline protects them from online attacks.

Proactive technical protections will help to keep personal records safe from cyber threat actors. Maintaining these measures paves the way to build a strong security posture for any organization.

Share this article

About the Author

Jordan Vector

Jordan Vector

Cybersecurity Expert

Jordan is a security researcher and advocate who focuses on making privacy practical. Whether he's explaining how to harden a browser or reporting on the latest surveillance disclosures, his goal is to equip readers with knowledge they can use immediately. Jordan believes that true security begins with understanding the digital landscape.

Comments (0)

No comments.