Skip to content
Data breachResolved

Houzz data breach (2018)

In mid-2018, the home-design platform Houzz had a file containing user data obtained by an unauthorized third party. The company learned of it in late 2018 and disclosed it in early 2019. Roughly 49 million accounts were exposed, including emails, usernames, salted password hashes and IP-derived locations.

Victim
Houzz
records
48.9M
users
48.9M

In mid-2018, the home-design and remodeling platform Houzz had a file containing user data obtained by an unauthorized third party. The company did not learn of it until late December 2018 and disclosed it publicly in early 2019. Roughly 49 million accounts were affected.

What happened

Houzz operates a website and apps for home renovation and interior design, connecting homeowners with professionals. In late December 2018, the company was notified that a file containing some of its user data was in the hands of third parties. Houzz engaged a forensics firm to investigate but was unable to determine precisely how the data left its environment β€” it stated publicly that it was not known whether the data was taken through a hacked system, an unsecured database or file, or by an insider. The breach is dated to around 23 May 2018 in breach-tracking records.

The company began notifying users and resetting passwords around 31 January 2019, and published a formal security update on 3 February 2019.

Data exposed

Houzz divided the exposed information into three categories:

  • Publicly visible profile data β€” names, locations, and any descriptions users had chosen to make public.
  • Internal account information β€” email address, user ID, prior Houzz usernames, one-way salted password hashes (uniquely salted per user), IP address, and the city and ZIP code inferred from the IP address.
  • Social-login identifiers β€” for users who signed in via Facebook, their public Facebook ID.

Houzz explicitly confirmed that no payment-card information, bank-account details or Social Security numbers were part of the breach.

Response

Houzz's response was widely cited as a relatively transparent example for a 2018-era incident: it proactively notified affected members, forced password resets, and provided guidance on password hygiene and phishing awareness. The unique per-user salting of password hashes meant the stolen credentials could not be trivially reversed in bulk, though, as with any breach involving password hashes, weak passwords remained crackable offline.

Why it matters

The Houzz breach illustrates two recurring themes. First, the detection gap: data believed taken in mid-2018 was only discovered when a third party surfaced it months later, leaving Houzz unable to fully reconstruct the intrusion. Second, it became a frequently-cited example of doing disclosure reasonably well β€” promptly notifying users and resetting passwords β€” even when the exact attack vector could not be established. For affected users, the main downstream risks were credential stuffing (for reused passwords) and targeted phishing using the leaked profile and location data.

Timeline

  1. The date later associated with the Houzz breach, when user data is believed to have been obtained.

  2. Houzz is notified in late December that a file containing user data is in the hands of third parties and begins an investigation with a forensics firm.

  3. Houzz starts notifying users and resetting passwords; the incident is first reported publicly.

  4. Houzz publishes its security update detailing the affected data.

  5. The 48.9-million-record dataset is added to Have I Been Pwned.

Sources

  1. haveibeenpwned.comhttps://haveibeenpwned.com/PwnedWebsites#Houzz
  2. techcrunch.comhttps://techcrunch.com/2019/01/31/houzz-data-breach/
  3. bleepingcomputer.comhttps://www.bleepingcomputer.com/news/security/houzz-break-in-data-breach-announced/
  4. malwarebytes.comhttps://www.malwarebytes.com/blog/security-world/business-security-world/2019/02/houzz-data-breach-why-informing-your-customers-is-the-right-call
  5. monitor.mozilla.orghttps://monitor.mozilla.org/en/breach-details/Houzz

Related incidents

Data breachResolved

Advance Auto Parts data breach (2024)

In June 2024, Advance Auto Parts confirmed they had suffered a data breach which was posted for sale to a popular hacking forum. Linked to unauthorised access to Snowflake cloud services, the breach exposed a large number of records related to both customers and employees.

Victim
Advance Auto Parts
Records
79.2M