[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f3vyn0ozltnvn9":3},{"success":4,"breach":5},true,{"_id":6,"name":7,"title":8,"slug":7,"domain":9,"breachDate":10,"addedDate":11,"modifiedDate":12,"contentUpdatedAt":13,"source":14,"sourceUrl":15,"sourceUrls":16,"pwnCount":20,"affectedCount":20,"affectedCountStatus":21,"affectedCountLowerBound":22,"affectedCountUnit":23,"hasEnglishDescription":4,"severity":24,"dataClasses":25,"description":38,"seoTitle":39,"seoTitleEn":40,"seoDescription":39,"seoDescriptionEn":41,"logoUrl":42,"isVerified":4,"isSensitive":4,"isSpamList":43,"isMalware":43,"company":44},"68e3266eda11adda4882514c","clixsense","ClixSense Data Breach","clixsense.com","2016-09-04T00:00:00.000Z","2016-09-11T06:37:25.000Z","2026-07-09T18:41:40.235Z","2026-07-18T23:47:49.242Z","Third party breach","https:\u002F\u002Fwww.ftc.gov\u002Fnews-events\u002Fnews\u002Fpress-releases\u002F2019\u002F04\u002Fftc-alleges-operators-two-commercial-websites-failed-protect-consumers-data",[15,17,18,19],"https:\u002F\u002Fwww.securityweek.com\u002F66-million-users-affected-clixsense-breach\u002F","https:\u002F\u002Fwww.techtarget.com\u002Fsearchsecurity\u002Fanswer\u002FWhat-caused-the-ClixSense-privacy-breach-that-exposed-user-data","https:\u002F\u002Fwww.helpnetsecurity.com\u002F2016\u002F09\u002F14\u002Fclixsense-users-exposed-hack\u002F",2424784,"known",null,"unknown","Critical",[26,27,28,29,30,31,32,33,34,35,36,37],"Account balances","Dates of birth","Email addresses","Genders","IP addresses","Names","Passwords","Payment histories","Payment methods","Physical addresses","Usernames","Website activity","\u003Cp>The ClixSense data breach is a large-scale security incident that occurred on September 4, 2016, affecting the online reward platform where users earn income by watching ads, completing surveys, and performing small online tasks. This record is being tracked based on 2,424,784 affected accounts. It is observed that the attackers claimed to have accessed a larger user base, but the publicly released and verified portion is associated with approximately 2.4 million accounts. This distinction is important to avoid confusing the total number of alleged records with the number of verified affected accounts.\u003C\u002Fp>\n\u003Cp>The verified data classes are quite extensive: account balances, birth dates, email addresses, gender information, IP addresses, names, plaintext passwords, payment histories, payment methods, physical addresses, usernames, and site activity. The inclusion of passwords in plaintext is particularly the most critical aspect of the incident. Payment method and payment history information can also provide clues about how users earn income through the platform; however, this field should not be expanded to include credit card numbers or bank account information. The record should be clearly explained and limited to the verified fields.\u003C\u002Fp>\n\u003Ch2>Leaking Data Types and Risks\u003C\u002Fh2>\n\u003Cp>The data fields in the ClixSense breach are of a nature that can affect both the user's account security and real-world identity. When an email address, username, and plaintext password are included together, an attacker can attempt direct logins on other services. Plaintext passwords are the riskiest form of password storage because they do not require hashing or guessing processes. If the user has used the same password for their email account, social media platforms, payment services, or other survey sites, the risk extends beyond the ClixSense account.\u003C\u002Fp>\n\u003Cp>Fields such as name, date of birth, gender, physical address, and IP address increase the risk of social engineering. Account balance, payment history, payment method, and site activity can provide context about the user's earning behavior on the platform. With this information, fake payment notifications, account balance refunds, reward confirmations, tax forms, survey payments, or profile update messages can be created. Users sharing personal and financial context information by trusting online extra income platforms can make attackers' messages more convincing.\u003C\u002Fp>\n\u003Ch2>Verified Scope and Boundaries\u003C\u002Fh2>\n\u003Cp>The number of verified affected accounts for this record is 2,424,784. Although it has been reported that the attackers referred to a larger data set, this record is maintained based on the verified and publicly reflected account coverage. The incident date is marked as September 4, 2016. The data classes are limited to account balance, date of birth, email address, gender, IP address, name, password, payment history, payment method, physical address, username, and site activity.\u003C\u002Fp>\n\u003Cp>In this record, the payment card number, bank account number, official identification document, social security number, or health data are not verified data classes. The payment method field should be understood as information about the user's payment preferences or in-platform payment type; it does not mean that the card number or bank account is included within a verified scope. Site activity refers to the context of the user's tasks, ads, surveys, or account movements on the platform; the level of detail in this field should not be considered the same for every user.\u003C\u002Fp>\n\u003Ch2>User Groups at Risk\u003C\u002Fh2>\n\u003Cp>Users at the highest risk are those who use the password from their ClixSense account on other accounts as well. Since the password is found in plain text, it is very easy for an attacker to try the same information on other sites. Email accounts, payment services, social media, shopping sites, and other survey\u002Freward platforms should be checked first. If the email account is compromised, the password reset links for other accounts may also fall into the attacker's hands.\u003C\u002Fp>\n\u003Cp>The second risk group consists of people who regularly use online extra income platforms and share payment method information on such services. Account balances and payment history can indicate that the user earns income from the platform. This information can be used for fake payment requests, tax notifications, reward transfers, or balance recovery messages. Users with a physical address and date of birth can be more personally targeted in phishing messages. From a corporate perspective, reusing passwords from personal reward accounts on work accounts poses a serious security risk.\u003C\u002Fp>\n\u003Ch2>Urgent Measures to Be Taken\u003C\u002Fh2>\n\u003Cp>The password used for ClixSense should no longer be considered secure. The user should change all accounts where the same or similar password is used. A unique and long password should be generated for each service using a password manager. Adding a number to the end of the old password, changing a letter, or using a similar pattern is not sufficient. Email accounts, payment services, social media accounts, and other income platforms should be prioritized for protection.\u003C\u002Fp>\n\u003Cp>Multi-factor authentication should be enabled on the email account, and recent sessions, connected devices, recovery addresses, and forwarding rules should be checked. Attention should be paid to messages themed around payments or surveys. Requests for account balance refunds, payment method updates, tax forms, gift cards, or profile verification should not be processed without verification through official channels. Messages asking the user for their current password, verification code, card information, or bank information should be considered high-risk.\u003C\u002Fp>\n\u003Ch2>Long-Term Security Strategies\u003C\u002Fh2>\n\u003Cp>The ClixSense incident shows that online reward and micro-task platforms should not be considered low-risk in terms of personal data. Fields such as name, address, date of birth, payment method, and account balance can be found together in such services. In the long term, users should consider using a separate email address for survey and reward services, deleting unnecessary profile information, and closing unused accounts. Payment method information should only be shared when necessary, and old payment records should be reviewed regularly.\u003C\u002Fp>\n\u003Cp>From a company perspective, storing passwords in plain text is unacceptable. Passwords should be protected with strong, modern, and slow password storage methods; access rights, old servers, and database connections should be regularly audited. Fields such as user balances and payment history should also be handled within the scope of personal data security. Corporate security teams should consider that employees might reuse passwords from personal side income platforms in their work accounts, and they should standardize leaked password checks and multi-factor authentication.\u003C\u002Fp>\n\u003Ch2>Record Control and User Action\u003C\u002Fh2>\n\u003Cp>A match in this record indicates that the relevant email address is among the accounts associated with the ClixSense data breach. A match does not mean that payment card or bank account information is included in the verified scope of this record; however, the risk is serious due to fields such as plain text passwords, account balance, payment history, and payment method. The user should first make sure that the same password is not used on any other accounts.\u003C\u002Fp>\n\u003Cp>After password changes are completed, sessions on email accounts and payment services should be checked. Unknown sessions should be closed, multi-factor authentication should be enabled, and recovery options should be updated. Messages themed around surveys, rewards, balance refunds, or payment updates should not be acted upon unless verified through official channels. Even if this incident is old, plain text passwords and payment-related information can still be used in phishing and automated login attempts many years later.\u003C\u002Fp>","","ClixSense Data Breach (2.4 Million Reported Records)","ClixSense Data Breach. 2.4 Million reported records were reported. Reported data: Account balances, Dates of birth, Email addresses. Review the scope, risks…","\u002Fuploads\u002Flogo\u002Fclixsense_com.webp",false,{"name":45,"sector":46,"country":47,"website":9,"websiteArchiveUrl":39,"websiteStatus":39,"websiteCheckedAt":22},"ClixSense","Online rewards and paid survey platform","United States"]