Skip to content
Data breachResolved

Tumblr data breach (2013)

A 2013 intrusion at the blogging platform Tumblr exposed roughly 65 million email addresses and salted SHA-1 password hashes; the scale only became public in 2016 when the data surfaced for sale on dark-web markets.

Victim
Tumblr
records
65.5M
users
65.5M

In early 2013, the blogging and social platform Tumblr suffered a data breach that exposed roughly 65 million user accounts. Although Tumblr acknowledged a credential-access incident in 2013, the true scale of the theft only became public in May 2016, when the dataset surfaced for sale on dark-web marketplaces as part of a wave of so-called "historical mega breaches."

What happened

The data was taken in early 2013, before Yahoo completed its acquisition of Tumblr later that year. On 12 May 2013, Tumblr posted a short security notice stating that a third party had obtained access to account information and that affected users would be required to reset their passwords. At the time the company did not quantify the exposure, and the incident attracted relatively little attention.

That changed three years later. In May 2016, a vendor known as "Peace" began listing the Tumblr database alongside other large historical breaches (LinkedIn, MySpace, Fling). Have I Been Pwned subsequently loaded 65,469,298 records into its index, confirming the breach involved tens of millions of accounts.

What was exposed

The leaked records contained email addresses and passwords stored as salted SHA-1 hashes. Crucially, Tumblr had salted its password hashes β€” adding random data to each password before hashing β€” which made bulk password cracking far less practical than in contemporaneous breaches that used unsalted MD5. As a result, the breach was widely regarded as exposing email addresses primarily, with the password hashes offering meaningful protection so long as the salts were not also compromised.

Impact

  • 65.5 million email addresses and salted SHA-1 password hashes circulated on underground markets.
  • Because of the strong hashing, the dataset's value was driven mainly by the email addresses, which fed spam, phishing, and credential-stuffing campaigns where users had reused passwords elsewhere.
  • Tumblr forced password resets and there was no evidence of plaintext password exposure.

Why it matters

Tumblr is frequently cited as the counter-example to the 2012–2013 mega-breach era: while LinkedIn, Last.fm, and MySpace stored passwords with weak or unsalted algorithms that were cracked en masse, Tumblr's decision to salt its SHA-1 hashes sharply limited the damage. It illustrates how a single hashing design choice can be the difference between a catastrophic credential dump and a comparatively contained email-address leak β€” even when the same number of accounts is stolen.

Timeline

  1. Attackers gain access to Tumblr user data, including email addresses and salted SHA-1 password hashes, before Yahoo's acquisition of the company.

  2. Tumblr publicly notes that a third party accessed account credentials and forces password resets, but does not disclose the scale.

  3. The breach resurfaces as part of a wave of 'historical mega breaches'; the dataset appears for sale on dark-web markets.

  4. Have I Been Pwned loads 65,469,298 Tumblr accounts; security researchers note the strong salted SHA-1 hashing limited password cracking.

Sources

  1. haveibeenpwned.comhttps://haveibeenpwned.com/breach/Tumblr
  2. vice.comhttps://www.vice.com/en/article/hackers-stole-68-million-passwords-from-tumblr-new-analysis-reveals/
  3. securityweek.comhttps://www.securityweek.com/65-million-users-affected-tumblr-breach/
  4. csoonline.comhttps://www.csoonline.com/article/556373/65-million-tumblr-account-records-are-up-for-sale-on-the-underground-market.html
  5. welivesecurity.comhttps://www.welivesecurity.com/2016/05/30/65-million-tumblr-users-probably-careful/

Related incidents

Data breachResolved

Adobe data breach (2013)

Attackers stole roughly 153 million Adobe account records β€” IDs, emails, weakly encrypted passwords and plaintext password hints β€” along with source code for several Adobe products, in one of the largest software-company breaches on record.

Victim
Adobe Systems
Loss
$1.0M
Records
152.4M
Data breachOngoing

Nintendo employee survey data stolen via third-party TinyPulse platform

Nintendo of America confirmed that threat actors stole internal employee survey data from TinyPulse, a third-party HR engagement platform it used, after the SHADOWBYT3$ group claimed to have exfiltrated about 859 MB of data and demanded a US$2 million ransom β€” while stressing that Nintendo's own systems and customer data were not affected.

Victim
Nintendo of America
Data breachRansom paid

Instructure Canvas LMS ShinyHunters breach (2026)

ShinyHunters exploited Canvas's Free-For-Teacher account programme to exfiltrate 3.65 TB of data spanning approximately 275 million users across nearly 9,000 schools β€” names, email addresses, student IDs, and some private messages between students and teachers. Instructure reportedly paid the ransom and the data was destroyed.

Victim
Instructure (Canvas LMS)
Loss
$10.0M
Records
275.0M