Skip to content
Data breachResolved

Wattpad data breach (2020)

In mid-2020, the user-generated stories platform Wattpad suffered a breach exposing roughly 268.8 million records, including names, email addresses, dates of birth, and bcrypt-hashed passwords. The database was first sold privately, then leaked for free on a hacking forum.

Victim
Wattpad
records
268.8M
users
268.8M

In mid-2020, the Toronto-based user-generated stories platform Wattpad suffered one of the largest consumer data breaches of the year, with roughly 268.8 million records stolen from its user database and ultimately leaked for free online.

What happened

In June 2020, attackers exfiltrated a copy of Wattpad's user database. The data was initially traded privately within cybercrime circles, reportedly priced at more than $100,000. By mid-July 2020 the database had been shared more widely, and security outlets including BleepingComputer reported the incident publicly on 15 July. Shortly afterward, the full dataset was posted for free on a popular hacking forum, ensuring its broad redistribution.

The threat actor group ShinyHunters was associated with the breach, though they claimed that the version they held contained password salts while the publicly released copy did not โ€” a discrepancy that fueled debate about how the data had moved through the underground market.

Data exposed

Analysis by Flashpoint and others put the dump at approximately 268,765,495 unique records. The exposed fields included:

  • Names and usernames
  • Email and IP addresses
  • Dates of birth and genders
  • Geographic location data
  • Profile bios, social-media profile links, and website URLs
  • Passwords stored as bcrypt hashes

Notably, the dataset contained nearly 3 million accounts tied to .mil email addresses, raising concern about exposure of U.S. military-affiliated users. Because passwords were protected with bcrypt โ€” a slow, salted hashing algorithm โ€” credential cracking was substantially harder than for breaches using fast hashes like unsalted MD5 or SHA-1.

Impact

The breach exposed a large volume of personal data that, even without easily reversible passwords, supported phishing, credential-stuffing, and social-engineering campaigns. Email/birth-date/location combinations are valuable for targeted fraud. Wattpad confirmed it was investigating, prompted affected users to reset passwords, and the dataset was loaded into Have I Been Pwned, where users could check exposure. A proposed class-action lawsuit followed in the United States.

Why it matters

Wattpad illustrates a now-familiar lifecycle for mega-breaches: quiet private sale, brief paid distribution, then a free public dump that permanently embeds the data into the criminal ecosystem. It also showcases a partial success story on the defensive side โ€” Wattpad's use of bcrypt meant the password hashes resisted mass cracking, limiting the most damaging outcome even as the rest of the profile data spread uncontrollably. For a platform whose user base skews young, the exposure of dates of birth and location data carried elevated privacy risk.

Timeline

  1. Wattpad's user database is exfiltrated and offered for private sale on cybercrime channels.

  2. Researchers observe an actor sharing the compromised Wattpad database, originally breached in June 2020.

  3. BleepingComputer and other outlets report the breach; the data is being sold for over $100,000.

  4. The full database is leaked for free on a public hacking forum, where it is broadly redistributed.

  5. Flashpoint analyzes the dump, counting roughly 268.8 million unique records including nearly 3 million .mil-affiliated addresses.

  6. Wattpad confirms it is investigating the incident and forces password resets; the breach is later loaded into Have I Been Pwned.

Sources

  1. haveibeenpwned.comhttps://haveibeenpwned.com/Breach/Wattpad
  2. bleepingcomputer.comhttps://www.bleepingcomputer.com/news/security/wattpad-data-breach-exposes-account-info-for-millions-of-users/
  3. flashpoint.iohttps://flashpoint.io/blog/wattpad-hack/
  4. betakit.comhttps://betakit.com/wattpad-investigating-reported-massive-data-breach-of-user-records/

Related incidents

Data breachResolved

Shopper+ data breach (2020)

In March 2023, "Canada's online shopping mall" Shopper+ disclosed a data breach discovered on a public hacking forum. The breach dated back to September 2020 and included 878k customer records with email and physical addresses, names, phone numbers and in some cases, genders and dates of birth.

Victim
Shopper+
Records
878.3K
Data breachResolved

MEO data breach (2020)

In early 2023, a corpus of data sourced from the New Zealand based face mask company MEO was discovered. Dating back to December 2020, the data contained over 8k customer records including names, addresses, phone numbers and passwords stored as MD5 Wordpress hashes.

Victim
MEO
Records
8.2K
Data breachResolved

NetGalley data breach (2020)

In December 2020, the book promotion site NetGalley suffered a data breach. The incident exposed 1.4 million unique email addresses alongside names, usernames, physical and IP addresses, phone numbers, dates of birth and passwords stored as salted SHA-1 hashes.

Victim
NetGalley
Records
1.4M