[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f20dte8in8295z":3},{"success":4,"breach":5},true,{"_id":6,"name":7,"title":8,"slug":7,"domain":9,"breachDate":10,"addedDate":11,"modifiedDate":12,"contentUpdatedAt":12,"source":13,"sourceUrl":14,"sourceUrls":15,"pwnCount":19,"affectedCount":19,"affectedCountStatus":20,"affectedCountLowerBound":21,"affectedCountUnit":22,"hasEnglishDescription":4,"severity":23,"dataClasses":24,"description":29,"seoTitle":30,"seoTitleEn":31,"seoDescription":30,"seoDescriptionEn":32,"logoUrl":33,"isVerified":4,"isSensitive":34,"isSpamList":34,"isMalware":34,"company":35},"68e3266eda11adda48825139","cashcrate","CashCrate Data Breach","cashcrate.com","2016-11-17T00:00:00.000Z","2018-04-20T21:40:38.000Z","2026-07-29T11:40:53.262Z","Third party breach","https:\u002F\u002Fdatabreach.com\u002Fbreach\u002Fcash-crate-2016",[14,16,17,18],"https:\u002F\u002Fwww.secureworld.io\u002Findustry-news\u002Fdata-breach-snags-6-million-cashcrate-users-data","https:\u002F\u002Fsecurityaffairs.com\u002F60083\u002Fdata-breach\u002Fcashcrate-data-breach.html","https:\u002F\u002Fwww.vice.com\u002Fen\u002Farticle\u002Fhackers-steal-6-million-user-accounts-for-cash-for-surveys-site\u002F",6844490,"known",null,"unknown","Critical",[25,26,27,28],"Email addresses","Names","Passwords","Physical addresses","\u003Cp>The CashCrate data breach is associated with the exposure of users' account information on the online survey and reward platform in an incident dated November 2016. Publicly available verifications indicate that the incident became news in 2017, the total impact was reported at approximately 6.8 million accounts, and the number of verified accounts was tracked as 6,844,490. CashCrate's pay-for-survey and offer completion model requires users to share personal contact information with the platform, so the leak is significant not only in terms of email and password security but also in terms of the potential misuse of physical addresses.\u003C\u002Fp>\n\u003Cp>The verified data fields are names, email addresses, physical addresses, and passwords. The password field is particularly critical because it has been reported that passwords in older accounts were stored in plain text, while in newer accounts they were stored as weak MD5 hashes. Plain text passwords can be tried directly, and weak hashes can be quickly cracked for short and predictable passwords. Therefore, a CashCrate registration carries a higher account takeover risk than a simple communication information leak. When evaluating the registration, unverified fields such as date of birth, phone number, payment card, or bank information should not be presented as part of this incident.\u003C\u002Fp>\n\u003Ch2>Leaking Data Types and Risks\u003C\u002Fh2>\n\u003Cp>In the CashCrate case, the verified types of data are email addresses, names, physical addresses, and passwords. The exposure of an email address together with name information makes targeted phishing messages more convincing. Physical address information, on the other hand, extends the risk beyond online account security; fake shipping, reward, sweepstakes, tax, or payment notifications can be prepared based on the user's location and delivery context. Such information can be used for social engineering purposes even years later, especially for users who have lived at the same address for a long time.\u003C\u002Fp>\n\u003Cp>The most critical aspect of the incident is that some of the passwords are in plain text while others are associated with weak MD5 hashes. A plain text password means that an attacker can attempt to log in to different services without needing any decryption process. Weak hash methods that can be quickly computed, like MD5, also do not provide sufficient protection against modern attack tools. If the user has used the same password for their email account, shopping site, social media, payment service, or work account, accounts other than CashCrate could also be at risk.\u003C\u002Fp>\n\u003Ch2>Verified Scope and Boundaries\u003C\u002Fh2>\n\u003Cp>The number of verified affected accounts for this record is 6,844,490. The incident date is considered to be November 2016, while the public disclosure of the breach occurred in 2017. The verified data classes are limited to name, email address, physical address, and password. It has been noted that in publicly available information, passwords are stored in plain text for some accounts, while MD5 hashes are used for newer accounts. Therefore, both scenarios should be considered in the password security assessment.\u003C\u002Fp>\n\u003Cp>In this record, fields such as phone number, date of birth, payment card, bank account, official ID number, or survey responses have not been added to the data classes because there is no equally verified evidence for them. Since physical address information has been verified, it should be treated as a separate risk category for user security. Additionally, the number of affected accounts does not prove the entire historical user base of the platform or that each row belongs to a unique individual; the number used here represents the scope of verified accounts.\u003C\u002Fp>\n\u003Ch2>User Groups at Risk\u003C\u002Fh2>\n\u003Cp>The users at the highest risk are those who use the password from their CashCrate account on other platforms as well. Using the same or a similar password as the email account is particularly dangerous because if the email account is compromised, access to other accounts can be gained through password reset links. If the same password has been used on shopping sites, payment services, or social media accounts, these will be the first places an attacker will try. If the physical address has also been leaked, it can make fraudulent messages appear more personalized.\u003C\u002Fp>\n\u003Cp>The second risk group consists of users who may naturally respond more quickly to messages themed around rewards, surveys, promotions, and shipping. Users of reward-based platforms like CashCrate may be familiar with payment notifications, sweepstakes results, shipping deliveries, or account verification messages. Attackers can exploit this expectation by sending fake links, malicious files, or forms requesting personal information. When the same name and address information is matched with different data sets, the user's online and offline profile can become more detailed.\u003C\u002Fp>\n\u003Ch2>Urgent Measures to Be Taken\u003C\u002Fh2>\n\u003Cp>The password used for CashCrate should not be considered secure. The user should first identify all accounts where the same password has been used and create unique, long, and hard-to-guess passwords for each. Email accounts, payment services, shopping sites, and social media accounts are especially a priority. A password manager should be used to prevent password reuse, and previously used passwords should not be reused with minor modifications. New passwords derived from the old password base can also be tried by attackers.\u003C\u002Fp>\n\u003Cp>Multi-factor authentication should be enabled on the email account, and recent sessions, recovery emails, phone numbers, and connected applications should be checked. Caution should be exercised against messages related to cargo, rewards, sweepstakes, survey payments, or tax refunds due to physical address information. No platform should request the user's password via email. Unexpected links should not be opened directly; the user should enter the address of the relevant service in the browser themselves. Suspicious payment or shipping notifications should not be processed without verification through official channels.\u003C\u002Fp>\n\u003Ch2>Long-Term Security Strategies\u003C\u002Fh2>\n\u003Cp>The CashCrate incident shows that the information held on reward and survey platforms is also highly valuable. Users should use a separate password for each service in the long term, close accounts that are no longer in use, and not store more personal information than necessary on platforms. Information such as a physical address should only be shared when truly necessary. If closing an account is not possible, unnecessary information in the profile should be deleted and a unique password should be used for the account. By using a separate email address for survey and reward services, the user can better protect their main email account.\u003C\u002Fp>\n\u003Cp>In terms of corporate security, repeated personal passwords should also be taken seriously. Employees should not use passwords from personal platforms on work accounts. Organizations can reduce this risk with policies that support multi-factor authentication, risky login detection, breached password checks, and the use of password managers. User awareness training should explain that not only major social media breaches, but also seemingly small reward and survey platforms, can be weak links in account security.\u003C\u002Fp>\n\u003Ch2>Record Control and User Action\u003C\u002Fh2>\n\u003Cp>A match with an email address in this record indicates that the related address appears on the verified account list in the CashCrate data breach. A match does not mean that all of the user's accounts have been compromised today; however, if the leaked password was used elsewhere, the risk may still persist. The first step is to try to remember the password used for CashCrate and change all accounts where the same password may have been used. If the password cannot be remembered, old password patterns used in 2016 should also be considered risky.\u003C\u002Fp>\n\u003Cp>Users should evaluate messages that come with name, email, and physical address information more carefully. Shipping, reward, or payment notifications that appear real can also be fake. Security alerts should be monitored after password changes, and if unexpected login notifications are received, all sessions in the relevant account should be closed. The lasting impact of this incident is primarily due to password reuse; therefore, a one-time password change should not be considered sufficient, and unique passwords and multi-factor authentication standards should be applied to all important accounts.\u003C\u002Fp>","","CashCrate Data Breach (6.8 Million Reported Records)","CashCrate Data Breach. 6.8 Million reported records were reported. Reported data: Email addresses, Names, Passwords. Review the scope, risks, and protective…","\u002Fuploads\u002Flogo\u002Fcashcrate_com.webp",false,{"name":36,"sector":37,"country":38,"website":9,"websiteArchiveUrl":39,"websiteStatus":40,"websiteCheckedAt":41},"CashCrate","Paid survey rewards platform","United States","https:\u002F\u002Fweb.archive.org\u002Fweb\u002F20240724020830\u002Fhttps:\u002F\u002Fcashcrate.com\u002F","archived","2026-07-29T11:30:22.391Z"]