Wattpad data breach (2020)
In mid-2020, the user-generated stories platform Wattpad suffered a breach exposing roughly 268.8 million records, including names, email addresses, dates of birth, and bcrypt-hashed passwords. The database was first sold privately, then leaked for free on a hacking forum.
- Victim
- Wattpad
- records
- 268.8M
- users
- 268.8M
In mid-2020, the Toronto-based user-generated stories platform Wattpad suffered one of the largest consumer data breaches of the year, with roughly 268.8 million records stolen from its user database and ultimately leaked for free online.
What happened
In June 2020, attackers exfiltrated a copy of Wattpad's user database. The data was initially traded privately within cybercrime circles, reportedly priced at more than $100,000. By mid-July 2020 the database had been shared more widely, and security outlets including BleepingComputer reported the incident publicly on 15 July. Shortly afterward, the full dataset was posted for free on a popular hacking forum, ensuring its broad redistribution.
The threat actor group ShinyHunters was associated with the breach, though they claimed that the version they held contained password salts while the publicly released copy did not โ a discrepancy that fueled debate about how the data had moved through the underground market.
Data exposed
Analysis by Flashpoint and others put the dump at approximately 268,765,495 unique records. The exposed fields included:
- Names and usernames
- Email and IP addresses
- Dates of birth and genders
- Geographic location data
- Profile bios, social-media profile links, and website URLs
- Passwords stored as bcrypt hashes
Notably, the dataset contained nearly 3 million accounts tied to .mil email addresses, raising concern about exposure of U.S. military-affiliated users. Because passwords were protected with bcrypt โ a slow, salted hashing algorithm โ credential cracking was substantially harder than for breaches using fast hashes like unsalted MD5 or SHA-1.
Impact
The breach exposed a large volume of personal data that, even without easily reversible passwords, supported phishing, credential-stuffing, and social-engineering campaigns. Email/birth-date/location combinations are valuable for targeted fraud. Wattpad confirmed it was investigating, prompted affected users to reset passwords, and the dataset was loaded into Have I Been Pwned, where users could check exposure. A proposed class-action lawsuit followed in the United States.
Why it matters
Wattpad illustrates a now-familiar lifecycle for mega-breaches: quiet private sale, brief paid distribution, then a free public dump that permanently embeds the data into the criminal ecosystem. It also showcases a partial success story on the defensive side โ Wattpad's use of bcrypt meant the password hashes resisted mass cracking, limiting the most damaging outcome even as the rest of the profile data spread uncontrollably. For a platform whose user base skews young, the exposure of dates of birth and location data carried elevated privacy risk.
Timeline
Wattpad's user database is exfiltrated and offered for private sale on cybercrime channels.
Researchers observe an actor sharing the compromised Wattpad database, originally breached in June 2020.
BleepingComputer and other outlets report the breach; the data is being sold for over $100,000.
The full database is leaked for free on a public hacking forum, where it is broadly redistributed.
Flashpoint analyzes the dump, counting roughly 268.8 million unique records including nearly 3 million .mil-affiliated addresses.
Wattpad confirms it is investigating the incident and forces password resets; the breach is later loaded into Have I Been Pwned.
Sources
- haveibeenpwned.comhttps://haveibeenpwned.com/Breach/Wattpad
- bleepingcomputer.comhttps://www.bleepingcomputer.com/news/security/wattpad-data-breach-exposes-account-info-for-millions-of-users/
- flashpoint.iohttps://flashpoint.io/blog/wattpad-hack/
- betakit.comhttps://betakit.com/wattpad-investigating-reported-massive-data-breach-of-user-records/