Evite data breach (2013)
An archived 2013 database from social-invitations site Evite was accessed by an attacker and later traded online, exposing roughly 101 million unique email addresses along with names, phone numbers, postal addresses, dates of birth and plaintext passwords.
- Victim
- Evite
- records
- 101.0M
- users
- 101.0M
On 11 August 2013, the social-planning website Evite β used to send and manage online event invitations β held customer data in an archive that would, six years later, become one of the largest consumer breaches surfaced through Have I Been Pwned. In April 2019, Evite discovered that an unauthorised third party had accessed an inactive database archive dating back to 2013, exposing roughly 101 million unique accounts.
What happened
According to Evite's own disclosure, an unauthorised party acquired an inactive data-storage file on 22 February 2019. The file contained dated user records from 2013 and earlier β information from accounts that were no longer active but had never been purged. Evite identified the unauthorised access during an internal investigation in April 2019 and posted a data-incident notice the following month.
The breach drew wider attention when a threat actor began advertising an Evite database for sale on a dark-web marketplace. Initial estimates put the exposure at around 10 million records, but in July 2019 a far larger dataset β 100,985,047 unique email addresses β was loaded into Have I Been Pwned, revealing the true scope.
Impact
- Roughly 101 million unique email addresses were exposed, most belonging to recipients of invitations rather than registered account holders.
- Compromised data classes included names, email addresses, phone numbers, physical addresses, dates of birth, genders and passwords.
- Critically, the passwords were stored in plain text, meaning no cracking was required to use them β a serious risk for anyone who reused those credentials elsewhere.
- Evite stated that no financial information or Social Security numbers were involved.
Why it matters
The Evite breach is a textbook case of the risk of forgotten legacy data. The exposed information sat in an inactive archive that served no operational purpose, yet remained accessible and unencrypted long after the accounts behind it went dormant. Had the records been deleted or properly secured under a data-retention policy, the incident would have been far smaller β or impossible.
It also underscores why plaintext password storage remains indefensible: a single archive compromise handed attackers directly usable credentials for 101 million users, many of whom likely reused those passwords on other services. The case is frequently cited alongside data-minimisation and retention requirements now embedded in privacy regimes such as the GDPR and California's CCPA.
Timeline
The exposed archive dates from this period; Evite's records in it pre-date 2014.
An unauthorised party acquires an inactive Evite data-storage file containing legacy user records from 2013 and earlier.
Evite identifies the unauthorised access to its database archive during an internal investigation.
Evite publishes a data-incident notice disclosing that a third party accessed its servers.
A threat actor lists an Evite database for sale on a dark-web marketplace, initially suggesting roughly 10 million records.
A dataset of 100,985,047 unique accounts is added to Have I Been Pwned, revealing the true scale of the breach.
Sources
- haveibeenpwned.comhttps://haveibeenpwned.com/Breach/Evite
- bleepingcomputer.comhttps://www.bleepingcomputer.com/news/security/evite-invites-over-100-million-people-to-their-data-breach/
- scworld.comhttps://www.scworld.com/news/data-dump-suggests-that-evite-data-breach-affected-100m-accounts
- datacenterknowledge.comhttps://www.datacenterknowledge.com/data-breaches/the-evite-breach-demonstrates-the-risk-of-losing-track-of-old-data