[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f3j9ca4eunhdk8":3},{"success":4,"breach":5},true,{"_id":6,"name":7,"title":8,"slug":9,"domain":10,"breachDate":11,"addedDate":12,"modifiedDate":12,"contentUpdatedAt":13,"source":14,"sourceUrl":15,"sourceUrls":16,"pwnCount":22,"affectedCount":22,"affectedCountStatus":23,"affectedCountLowerBound":24,"affectedCountUnit":25,"hasEnglishDescription":4,"severity":26,"dataClasses":27,"description":32,"seoTitle":33,"seoTitleEn":34,"seoDescription":33,"seoDescriptionEn":35,"logoUrl":36,"isVerified":4,"isSensitive":37,"isSpamList":37,"isMalware":37,"company":38},"68e3266eda11adda48825166","CutoutPro","Cutout.Pro Data Breach","cutoutpro","cutout.pro","2024-02-26T00:00:00.000Z","2024-02-28T22:16:27.000Z","2026-07-19T21:05:33.381Z","Database leak","https:\u002F\u002Ftwitter.com\u002FH4ckManac\u002Fstatus\u002F1762387053889675658",[15,17,18,19,20,21],"https:\u002F\u002Fwww.bleepingcomputer.com\u002Fnews\u002Fsecurity\u002F20-million-cutoutpro-user-records-leaked-on-data-breach-forum\u002F","https:\u002F\u002Fwww.bitdefender.com\u002Fen-us\u002Fblog\u002Fhotforsecurity\u002Fhacker-leaks-records-20-million-users-ai-visual-creation-platform-online","https:\u002F\u002Fwww.cutout.pro\u002Fabout","https:\u002F\u002Fwww.cutout.pro\u002Fprivacy","https:\u002F\u002Fwww.cutout.pro\u002Fterms",19972829,"known",null,"unknown","Critical",[28,29,30,31],"Email addresses","IP addresses","Names","Passwords","\u003Cp>\u003Cstrong>The Cutout.Pro data breach\u003C\u002Fstrong> exposed email, name, IP-address and password data linked to 19,972,829 accounts in February 2024.\u003C\u002Fp>\u003Ch2>Types of Exposed Data and Risks\u003C\u002Fh2>\u003Cp>\u003Cstrong>The confirmed data classes\u003C\u002Fstrong> are email addresses, IP addresses, names and passwords. Passwords were not stored in plain text; they were represented as salted MD5 hashes. A salt causes identical passwords to produce different hashes and provides protection against precomputed rainbow tables, but MD5 is a fast and weak algorithm for modern password storage. Short, common or dictionary-based passwords therefore remain vulnerable to offline guessing. Combining an email address with a name can support targeted phishing, while an IP address may reveal approximate network or regional context. Phone numbers, physical addresses, payment cards and the photo or video files processed by users are not among the confirmed data classes. The 19,972,829 figure on this page is the canonical verified account scope and must not be added to the rounded “20 million” description.\u003C\u002Fp>\u003Ch2>Breach Timeline and Technical Details\u003C\u002Fh2>\u003Cp>The canonical breach date is 26 February 2024. The first public alert that roughly 20 million user records had been posted on a cybercrime forum appeared on 27 February; independent reports on 29 February and 4 March brought the incident to a wider audience. The verified entry was added to the breach catalogue on 28 February. Records were directly attributed to Cutout.Pro accounts and validated against the four canonical fields. Salted MD5 hashes are not directly readable passwords, but MD5's computational speed enables an attacker to test large numbers of password candidates. Reliable sources did not establish the initial access path, the vulnerability used or how long an intruder may have retained access, so those details are not inferred here. This is a verified database leak attributed to Cutout.Pro infrastructure, not a password compilation assembled from unrelated websites or output from information-stealing malware.\u003C\u002Fp>\u003Ch2>User Groups at Risk\u003C\u002Fh2>\u003Cp>People at greatest risk are those who created a Cutout.Pro account by February 2024. Anyone who reused the same password for email, social media, cloud storage, a design tool or another AI service faces a greater account-takeover risk. A salted MD5 hash is not the password itself, but if a weak password is guessed offline, the recovered value can be tried against other services. Design agencies, e-commerce teams, photographers and developers using the service's programmatic tools may receive targeted fake invoices, quota alerts, subscription renewals or file-sharing messages because their business email addresses provide useful context. An IP address may indicate an approximate connection region or corporate network provider, but it does not establish a precise location. This record does not confirm that processed image files were exposed, so it should not be interpreted as evidence that users' private photographs were leaked.\u003C\u002Fp>\u003Ch2>Immediate Steps to Take\u003C\u002Fh2>\u003Cp>\u003Cstrong>Your first priority\u003C\u002Fstrong> is to replace the password used for Cutout.Pro during the breach period anywhere it remains in use with a strong, unique password. Secure the associated email account first because password-reset links and security notifications may arrive there. Enable multi-factor authentication on email, cloud-storage, payment and design accounts, preferring an authenticator app, passkey or hardware security key where available. Review active Cutout.Pro sessions, connected applications and programmatic access keys; close sessions you do not recognize and rotate suspicious keys. Start a password change by typing cutout.pro into the browser instead of following a link in a message. Check the sender domain on messages designed to create urgency, such as “your file was processed”, “your credits expired” or “your subscription was suspended”. \u003C\u002Fp>\u003Ch2>Long-Term Security Strategies\u003C\u002Fh2>\u003Cp>Creating a random, unique password for each service prevents one cracked password hash from affecting other accounts. Store credentials in a trusted password manager and protect its primary account with strong multi-factor authentication. Use passkeys where available to reduce reliance on passwords. For team accounts, assign individual users and role-based permissions instead of sharing one login, and promptly remove access for former staff. Never place programmatic access keys in source code, public repositories or support messages; rotate them regularly and grant only the permissions required. Assess the sensitivity of client files before uploading them to an image-processing service, remove unnecessary identity documents or metadata and review contractual retention terms. Continuous breach notifications can help you respond quickly if the same email address appears in another incident.\u003C\u002Fp>\u003Ch2>Check Your Data\u003C\u002Fh2>\u003Cp>To learn whether you appear in the Cutout.Pro record, check every current and former email address that you may have used by 2024 through a trusted breach-search service. A match means the address appears in a verified dataset that may include a name, IP address and salted MD5 password hash. It does not prove that the password was successfully cracked, but it is sufficient warning to stop treating that password as safe. Include former corporate addresses because a closed mailbox can remain in a historical record while the same password may still be active elsewhere. Record the result without redistributing personal data and prioritize password changes beginning with email, financial and cloud accounts. Do not search another person's address without permission; use the information only to protect your own accounts or organizational assets that you are authorized to administer.\u003C\u002Fp>","","Cutout.Pro Data Breach (20 Million Reported Records)","Cutout.Pro Data Breach. 20 Million reported records were reported. Reported data: Email addresses, IP addresses, Names. Review the scope, risks, and…","\u002Fuploads\u002Flogo\u002Fcutout_pro.webp",false,{"name":39,"sector":40,"country":41,"website":10,"websiteArchiveUrl":33,"websiteStatus":33,"websiteCheckedAt":24},"Cutout.Pro (LibAI team)","Technology","Hong Kong"]