Tumblr data breach (2013)
A 2013 intrusion at the blogging platform Tumblr exposed roughly 65 million email addresses and salted SHA-1 password hashes; the scale only became public in 2016 when the data surfaced for sale on dark-web markets.
- Victim
- Tumblr
- records
- 65.5M
- users
- 65.5M
In early 2013, the blogging and social platform Tumblr suffered a data breach that exposed roughly 65 million user accounts. Although Tumblr acknowledged a credential-access incident in 2013, the true scale of the theft only became public in May 2016, when the dataset surfaced for sale on dark-web marketplaces as part of a wave of so-called "historical mega breaches."
What happened
The data was taken in early 2013, before Yahoo completed its acquisition of Tumblr later that year. On 12 May 2013, Tumblr posted a short security notice stating that a third party had obtained access to account information and that affected users would be required to reset their passwords. At the time the company did not quantify the exposure, and the incident attracted relatively little attention.
That changed three years later. In May 2016, a vendor known as "Peace" began listing the Tumblr database alongside other large historical breaches (LinkedIn, MySpace, Fling). Have I Been Pwned subsequently loaded 65,469,298 records into its index, confirming the breach involved tens of millions of accounts.
What was exposed
The leaked records contained email addresses and passwords stored as salted SHA-1 hashes. Crucially, Tumblr had salted its password hashes β adding random data to each password before hashing β which made bulk password cracking far less practical than in contemporaneous breaches that used unsalted MD5. As a result, the breach was widely regarded as exposing email addresses primarily, with the password hashes offering meaningful protection so long as the salts were not also compromised.
Impact
- 65.5 million email addresses and salted SHA-1 password hashes circulated on underground markets.
- Because of the strong hashing, the dataset's value was driven mainly by the email addresses, which fed spam, phishing, and credential-stuffing campaigns where users had reused passwords elsewhere.
- Tumblr forced password resets and there was no evidence of plaintext password exposure.
Why it matters
Tumblr is frequently cited as the counter-example to the 2012β2013 mega-breach era: while LinkedIn, Last.fm, and MySpace stored passwords with weak or unsalted algorithms that were cracked en masse, Tumblr's decision to salt its SHA-1 hashes sharply limited the damage. It illustrates how a single hashing design choice can be the difference between a catastrophic credential dump and a comparatively contained email-address leak β even when the same number of accounts is stolen.
Timeline
Attackers gain access to Tumblr user data, including email addresses and salted SHA-1 password hashes, before Yahoo's acquisition of the company.
Tumblr publicly notes that a third party accessed account credentials and forces password resets, but does not disclose the scale.
The breach resurfaces as part of a wave of 'historical mega breaches'; the dataset appears for sale on dark-web markets.
Have I Been Pwned loads 65,469,298 Tumblr accounts; security researchers note the strong salted SHA-1 hashing limited password cracking.
Sources
- haveibeenpwned.comhttps://haveibeenpwned.com/breach/Tumblr
- vice.comhttps://www.vice.com/en/article/hackers-stole-68-million-passwords-from-tumblr-new-analysis-reveals/
- securityweek.comhttps://www.securityweek.com/65-million-users-affected-tumblr-breach/
- csoonline.comhttps://www.csoonline.com/article/556373/65-million-tumblr-account-records-are-up-for-sale-on-the-underground-market.html
- welivesecurity.comhttps://www.welivesecurity.com/2016/05/30/65-million-tumblr-users-probably-careful/