[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f375ffl43b7gyl":3},{"success":4,"breach":5},true,{"_id":6,"name":7,"title":8,"slug":7,"domain":9,"breachDate":10,"addedDate":11,"modifiedDate":12,"contentUpdatedAt":13,"source":14,"sourceUrl":15,"sourceUrls":16,"pwnCount":19,"affectedCount":19,"affectedCountStatus":20,"affectedCountLowerBound":21,"affectedCountUnit":22,"hasEnglishDescription":4,"severity":23,"dataClasses":24,"description":31,"seoTitle":32,"seoTitleEn":33,"seoDescription":32,"seoDescriptionEn":34,"logoUrl":35,"isVerified":4,"isSensitive":4,"isSpamList":36,"isMalware":36,"company":37},"68e3266eda11adda48825140","chatbooks","Chatbooks Data Breach","chatbooks.com","2020-03-26T00:00:00.000Z","2020-07-29T21:21:46.000Z","2026-07-09T18:15:39.420Z","2026-07-18T23:47:21.289Z","Third party breach","https:\u002F\u002Fwww.bleepingcomputer.com\u002Fnews\u002Fsecurity\u002Fchatbooks-discloses-data-breach-after-data-sold-on-dark-web\u002F",[15,17,18],"https:\u002F\u002Fwww.bitdefender.com\u002Fen-us\u002Fblog\u002Fhotforsecurity\u002Fchatbooks-security-breach-users-told-to-change-their-passwords","https:\u002F\u002Fcyberscoop.com\u002Fchatbooks-data-breach-shiny-hunters\u002F",2520441,"known",null,"unknown","Critical",[25,26,27,28,29,30],"Email addresses","Names","Passwords","Phone numbers","Social media profiles","Auth tokens","\u003Cp>Chatbooks became a topic of discussion after the photo printing and photo book service platform experienced a data leak in March 2020 associated with unauthorized access. Publicly available verifications indicate that the dataset contains approximately 15 million user records, but the number of verified accounts tracked through unique email addresses is 2,520,441. This distinction is important; the total record volume should not be interpreted directly as the number of unique individuals due to repeating rows belonging to the same person or different types of records within the platform.\u003C\u002Fp>\n\u003Cp>The confirmed main data classes for this record are email addresses, names, phone numbers, social media profiles, and passwords. Passwords are stored not in plain text, but in a salted SHA-512 hash form. Although this is a better situation than having plain text passwords, if the password is weak or has been used before, the risk is not completely eliminated. Some reports mention social media access tokens in a small portion of the records; therefore, this field should be considered a limited additional risk. Photo contents, photo metadata, or family albums themselves should not be treated as confirmed data classes for this record.\u003C\u002Fp>\n\u003Ch2>Leaked Data Types and Risks\u003C\u002Fh2>\n\u003Cp>The main risk in the Chatbooks case is that the name, email address, phone number, and social media profile information can be linked to the same user. This combination allows attackers to send messages that appear realistic to the user. In the context of the photo book and memory printing service, scams themed around family, special occasions, gifts, orders, and delivery can become more convincing. Users with a phone number can be targeted via text messages and calls; users with a social media profile may face risks of being followed, impersonated, or having their profile matched across different platforms.\u003C\u002Fp>\n\u003Cp>Storing passwords in salted SHA-512 hash form provides better protection than plain text password leaks; however, it is not sufficient security on its own. Short, predictable, or passwords seen in other leaks can still be cracked. The risk increases if the user has reused the same password on email, social media, photo services, shopping, or cloud storage accounts. Information that social media access tokens are present in a small portion should also be taken into account; even if they are invalid or expired, these fields can help attackers understand social media connections and account relationships.\u003C\u002Fp>\n\u003Ch2>Verified Scope and Boundaries\u003C\u002Fh2>\n\u003Cp>The number of affected accounts for this record is listed as 2,520,441. The larger figure of approximately 15 million records refers to the total row or object volume in the dataset; it should not be interpreted as the number of unique users. Verified data classes include names, email addresses, phone numbers, social media profiles, password hashes, and limited access token risk. It should be specifically noted that the passwords are not in plaintext and are in salted SHA-512 hash format.\u003C\u002Fp>\n\u003Cp>In this record, there is no verified evidence of photo files, family albums, photo metadata, payment cards, bank information, physical addresses, or official identification numbers. The fact that Chatbooks is a photo-focused service does not mean that photo content is among the verified data fields of this record. The description should maintain this distinction; otherwise, the user would be informed of a higher risk than the actual scope. Social media profile and possible access token information should not be confused with photo content, and should be considered as a separate account connection risk.\u003C\u002Fp>\n\u003Ch2>User Groups at Risk\u003C\u002Fh2>\n\u003Cp>Users at the highest risk are those who use the password from their Chatbooks account on other accounts as well. Email accounts, social media accounts, cloud photo storage services, and shopping accounts should be checked in particular. Since photo printing services are often associated with family members, special occasions, and gifts, attackers may prepare messages that create an emotional connection. For example, titles such as order notification, family album link, shipping alert, or gift discount can be used to persuade the user to click on the link.\u003C\u002Fp>\n\u003Cp>Users whose phone number or social media profile is included in the registration also face a multi-channel targeting risk. An attacker may first send an email and then follow up with a message via SMS or social media to reinforce the impression that the message is legitimate. For individuals whose social media account is public, information such as family members, friend lists, photo-sharing habits, and special occasions can also be visible. Therefore, the risk is not limited to the Chatbooks account; the user's visibility on other platforms is also important.\u003C\u002Fp>\n\u003Ch2>Urgent Measures to Be Taken\u003C\u002Fh2>\n\u003Cp>Users should change the password they use for their Chatbooks account and set unique new passwords for all accounts where the same password is used. Even if the password has not been leaked in plaintext, weak or reused passwords can be cracked over time and tried on other services. Using a password manager makes it easier to create different and long passwords for each service. Email accounts and social media accounts should be protected as a priority, because these accounts are used for password resets and authentication on other services.\u003C\u002Fp>\n\u003Cp>Two-factor authentication should be enabled on email and social media accounts. Users should be cautious of links in unexpected messages related to Chatbooks, photo printing, shipping, discounts, family albums, or gifts. Connected applications, authorized sessions, and third-party accesses on social media accounts should be checked. Unknown applications should be removed, old sessions should be closed, and security alerts should be kept on. Verification codes or password requests received by phone should never be shared under any circumstances.\u003C\u002Fp>\n\u003Ch2>Long-Term Security Strategies\u003C\u002Fh2>\n\u003Cp>Photography and memory services are related to users' private lives; therefore, account security should not be seen solely as a technical issue. In the long term, separate and strong passwords should be used for family, photography, cloud storage, and social media accounts. Unnecessary connections in services linked via social media should be regularly removed, and only actively used applications should be allowed. Account closure or data deletion options should be reviewed at certain intervals.\u003C\u002Fp>\n\u003Cp>For institutions, such violations indicate that personal data kept in social media-linked entry and photo services need to be carefully classified. Access tokens, password hashes, and profile connections should be protected with separate security controls. For users, the most practical strategy is to separate accounts shared for sensitive moments and family services from social media accounts whenever possible, limit account permissions, and verify unexpected photo or delivery-themed messages through official channels.\u003C\u002Fp>\n\u003Ch2>Record Control and User Action\u003C\u002Fh2>\n\u003Cp>A match in this record indicates that the relevant email address is included in the unique email list monitored under the Chatbooks data breach. A match does not mean that the user's photos or family albums have been compromised. The verified risk relates to fields such as name, email, phone, social media profile, password hash, and limited access token. The user should first change accounts where the same password may have been used and check social media connections.\u003C\u002Fp>\n\u003Cp>The next step is to establish a permanent level of vigilance against fraud messages themed around photos and social media. Messages such as those involving a shipment, photo book, special day discount, or family album link should be verified through the official application or domain, even if they appear legitimate. Extra caution should be exercised with links received via text messages, as the phone number may have been included in a registration. If unknown sessions or connected applications are seen on social media accounts, they should be removed and the password should be changed again.\u003C\u002Fp>","","Chatbooks Data Breach (2.5 Million Reported Records)","Chatbooks Data Breach. 2.5 Million reported records were reported. Reported data: Email addresses, Names, Passwords. Review the scope, risks, and protective…","\u002Fuploads\u002Flogo\u002Fchatbooks_com.webp",false,{"name":38,"sector":39,"country":40,"website":9,"websiteArchiveUrl":32,"websiteStatus":32,"websiteCheckedAt":21},"Chatbooks","Photo printing and photo book service","United States"]