[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f24hdsqaev4k3i":3},{"success":4,"breach":5},true,{"_id":6,"name":7,"title":8,"slug":9,"domain":10,"breachDate":11,"addedDate":12,"publishedAt":13,"modifiedDate":14,"contentUpdatedAt":15,"source":16,"sourceUrl":17,"sourceUrls":18,"pwnCount":26,"affectedCount":26,"affectedCountStatus":27,"affectedCountLowerBound":13,"affectedCountUnit":28,"hasEnglishDescription":4,"contentLocale":29,"availableLocales":30,"translations":32,"severity":35,"dataClasses":36,"description":41,"seoTitle":42,"seoDescription":43,"logoUrl":44,"isVerified":45,"isSensitive":45,"isSpamList":45,"isMalware":45,"company":46},"6a46d2c11863665f66ce5f47","Couchsurfing 2020","Couchsurfing (2020) Alleged Data Exposure","couchsurfing-2020","couchsurfing.com","2020-07-01T00:00:00.000Z","2020-07-20T07:00:00.000Z",null,"2026-09-17T16:27:41.515Z","2026-07-20T00:25:15.423Z","Reported account database sale","https:\u002F\u002Fwww.zdnet.com\u002Farticle\u002Fcouchsurfing-investigating-data-breach-after-17-million-user-records-leak\u002F",[17,19,20,21,22,23,24,25],"https:\u002F\u002Fwww.zdnet.fr\u002Factualites\u002Fles-donnees-de-17-millions-d-utilisateurs-du-site-couchsurfing-fuitent-sur-la-toile-39907119.htm","https:\u002F\u002Fwww.darkreading.com\u002Fattacks-breaches\u002Fcouchsurfing-investigates-potential-data-breach\u002Fd\u002Fd-id\u002F1338437","https:\u002F\u002Fabout.couchsurfing.com\u002Fabout\u002Fabout-us\u002F","https:\u002F\u002Fabout.couchsurfing.com\u002Fabout\u002Fprivacy-policy\u002F","https:\u002F\u002Fwww.couchsurfing.com\u002F","https:\u002F\u002Fproduction-origin-cdn.couchsurfing.com\u002Fimages\u002Fbrand.svg","https:\u002F\u002Fnews.google.com\u002Frss\u002Farticles\u002FCBMirgFBVV95cUxOWndZNmF2OEdEYlBLQVVpdVFXc0tCekNyMU83Yy1mOGRvTVdYNC12QW9CaUF0MTM0Sy04eldSbHN1M01vdTB3dUtzRHFScEJUNFhsRzBvWGRtMC1IZ1k2M1RZYzhIQzZ0R3NoRE9iQ1BmOHM5QV9TNlN0ZWNoUVRjU1pqQ0xoS2x5M1EwaDFhZmEwWVNwTlRDdHdhQmFDRWdGOXRsOVJTb2RTRUpMTmc?oc=5",17000000,"known","email_identifiers","en",[29,31],"tr",{"en":33,"tr":34},{"slug":9},{"slug":9},"Critical",[37,38,39,40],"Account settings","Email addresses","Names","User IDs","\u003Cp>The reported July 2020 Couchsurfing data breach involved about 17 million accounts and exposed emails, names, user IDs and account settings.\u003C\u002Fp>\u003Ch2>Types of Exposed Data and Risks\u003C\u002Fh2>\u003Cp>The sample reviewed at the time and contemporaneous reporting identified email addresses, real names, user IDs and account settings in the data offered for sale. \u003Cstrong>Passwords were specifically reported as absent from the sale package\u003C\u002Fstrong>, so the record must not claim that password hashes, plaintext passwords or direct login credentials were exposed. Reliable evidence also does not establish that phone numbers, payment cards, private messages, identity documents, precise locations, travel histories or profile narratives were present. Combining an email address, name and platform-specific user ID can still enable targeted phishing, spam, fraudulent support messages and correlation with profiles found in public sources. The figure of about 17 million describes advertised account records rather than a fully verified count of unique people.\u003C\u002Fp>\u003Ch2>Breach Timeline and Technical Details\u003C\u002Fh2>\u003Cp>The dataset appeared during the first part of July 2020, initially in private messaging channels and later on public criminal forums. The seller claimed the records had been taken from Couchsurfing servers and offered the package for US$700. A small sample provided to security reporters contained user IDs, real names, email addresses and account-setting fields. The company said it had engaged an external cybersecurity firm to investigate and had contacted law enforcement. No public final incident report established the exact access date or a confirmed intrusion method. A misplaced backup file was proposed as one possible source, but that was a theory rather than a demonstrated root cause. The record therefore uses early July 2020 as the incident period without claiming day-level precision. Structured Couchsurfing account fields distinguish the material from a generic credential collection, while the absence of conclusive public validation requires the record to remain qualified.\u003C\u002Fp>\u003Ch2>User Groups at Risk\u003C\u002Fh2>\u003Cp>The greatest exposure applies to people who had a Couchsurfing account before 2020 and used their real name with a primary email address. Knowing the platform, account existence and user ID lets an attacker construct convincing notices about security, membership charges, profile verification, hosting requests or travel messages. \u003Cstrong>The absence of passwords from the reported dataset does not eliminate account-takeover risk\u003C\u002Fstrong>: attackers can still use email to steal a password-reset link, request a one-time code or direct a member to a fraudulent sign-in page. If the same email appears on other services, the records can support profile correlation and personalized fraud. Historical identity data can make scams credible years later. Presence in the sale package does not prove that an account was accessed, private messages were read those conclusions require separate evidence.\u003C\u002Fp>\u003Ch2>Immediate Steps to Take\u003C\u002Fh2>\u003Cp>If your 2020-era Couchsurfing password is still in use, or if you reused it elsewhere, replace every copy with a long, unique password as a precaution even though passwords were not reported in this package. Secure the primary email account first: review unfamiliar sessions, forwarding rules and recovery addresses, then enable multi-factor authentication. Check profile, privacy and communication settings in Couchsurfing and report changes you did not make through the official support channel. Do not follow links in messages about membership renewal, payment problems, profile approval, hosting requests or emergency travel assistance. Open the site or app independently and inspect the sender's domain. Do not assume that someone who knows your name or user ID is a genuine employee, host or traveler. Never disclose a password, one-time code or payment information in response to an unsolicited message; confirm the request through a separate trusted channel.\u003C\u002Fp>\u003Ch2>Long-Term Security Strategies\u003C\u002Fh2>\u003Cp>Use a password manager to generate a unique credential for every service so a future credential leak from another source cannot spread across accounts. Keep multi-factor authentication enabled on email and regularly review recovery options; travel-related messages can begin an attempt to compromise the associated mailbox. Reduce the visibility of unnecessary real-name details, personal links and profile text when they are publicly accessible. Close travel accounts you no longer use, remove obsolete third-party connections and terminate old sessions periodically. \u003Cstrong>A message containing genuine account details does not prove its sender is legitimate\u003C\u002Fstrong>; breach data helps criminals create accurate-looking context. Monitor unexpected password-reset, new-session and email-change alerts. Follow later security notices only through the organization's official domain.\u003C\u002Fp>\u003Ch2>Check Your Data\u003C\u002Fh2>\u003Cp>Use the secure search field on this page to check each current and historical email address you may have used with Couchsurfing before 2020. A match may show that the address appears in records associated with this event; it does not mean the password was exposed, the account was taken over or the complete profile became public. If you receive a result, identify the mailbox used for the account, review its security history and Couchsurfing settings, and eliminate reused passwords. No result is an absolute guarantee because the dataset may be incomplete, an address may have been written differently or another incident may apply. Enter only the supported identifier; never submit a password, one-time code, payment card or private-message content to a breach checker. If an unexpected alert appears, avoid its embedded link and reach your account through the official application or domain.\u003C\u002Fp>","Couchsurfing (2020) Alleged Data Exposure (17 Million Email Identifiers)","Couchsurfing (2020) Alleged Data Exposure. 17 Million email identifiers are reported. Reported data: Account settings, Email addresses, Names. Review the…","\u002Fuploads\u002Flogo\u002Fcouchsurfing-com-6a46d2c11863665f66ce5f47-4d57043.webp",false,{"name":47,"sector":48,"country":49,"website":10,"websiteArchiveUrl":50,"websiteStatus":50,"websiteCheckedAt":13},"Couchsurfing International, Inc.","Hospitality exchange and social networking","United States",""]