Skip to content
Data breachResolved

Gravatar data scraping (2020)

In October 2020, a researcher disclosed that Gravatar's profile API could be enumerated without rate limiting. 167 million names, usernames, and email-hash records were scraped, and 114 million of the MD5 hashes were cracked to reveal email addresses.

Victim
Gravatar
records
114.0M
users
114.0M

In October 2020, security researcher Carlo Di Dato disclosed that Gravatar β€” the globally recognised avatar service used by WordPress and countless other platforms β€” allowed its user-profile data to be enumerated at scale with virtually no rate limiting. The technique enabled mass scraping that ultimately exposed data on more than 100 million users.

What happened

Gravatar assigns every account a profile reachable via a predictable MD5 hash of the user's email address, and exposes profile data through a JSON API. Di Dato demonstrated two problems: the API returned rich profile data, and Gravatar had "virtually no rate limiting", meaning an automated scraper could request millions of profiles unchallenged. An additional method allowed fetching profiles by their sequential numeric ID, making bulk enumeration trivial.

Using these weaknesses, scrapers collected 167 million names, usernames, and MD5-hashed email addresses. Because MD5 is a fast, unsalted hash, 114 million of those hashes were subsequently cracked, reversing them back to the original email addresses and pairing them with the associated names and usernames.

Is it a "breach"?

Gravatar pushed back on the term "breach," arguing the data was publicly accessible by design rather than stolen from a protected database. Strictly, no system was penetrated β€” but the practical outcome was identical to a breach: a large, enriched dataset of names, usernames, and email addresses entered the hacking community. Have I Been Pwned indexed it precisely because affected users had no way to know their data had been harvested.

Impact

  • Roughly 113,990,759 records with names, usernames, and cracked email addresses were distributed.
  • The data is well-suited to targeted phishing and spam, since it links real names and usernames to email addresses.
  • Because email addresses are immutable identifiers, affected users cannot simply "reset" them β€” the exposure is durable.
  • Gravatar said it took steps to close the enumeration vector and curb further bulk downloads after the disclosure.

Why it matters

The Gravatar incident is a defining example of scraping-as-breach: data that an organisation considers "public" can be aggregated, cracked, and weaponised at a scale the original design never anticipated. It underscores two enduring lessons β€” MD5 is unfit for protecting identifiers, and rate limiting plus access controls on profile APIs are security features, not niceties. For platforms that expose user data through predictable identifiers, the case is a reminder that enumeration resistance matters as much as preventing outright intrusion.

Timeline

  1. Security researcher Carlo Di Dato publicly demonstrates that Gravatar profile data can be enumerated via its JSON API with virtually no rate limiting.

  2. Gravatar states it has taken steps to close the enumeration vector and limit further bulk downloads.

  3. A dataset of roughly 167 million scraped records circulates in the hacking community; 114 million MD5 email hashes are cracked.

  4. The 114 million-record dataset is loaded into Have I Been Pwned, prompting renewed public attention.

Sources

  1. haveibeenpwned.comhttps://haveibeenpwned.com/PwnedWebsites#Gravatar
  2. bleepingcomputer.comhttps://www.bleepingcomputer.com/news/security/online-avatar-service-gravatar-allows-mass-collection-of-user-info/
  3. searchenginejournal.comhttps://www.searchenginejournal.com/gravatar-breach/429282/
  4. itnews.com.auhttps://www.itnews.com.au/news/gravatar-profile-add-on-leaks-data-on-millions-of-users-573607

Related incidents

Data breachResolved

Advance Auto Parts data breach (2024)

In June 2024, Advance Auto Parts confirmed they had suffered a data breach which was posted for sale to a popular hacking forum. Linked to unauthorised access to Snowflake cloud services, the breach exposed a large number of records related to both customers and employees.

Victim
Advance Auto Parts
Records
79.2M