[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f1ixdkzezprl5j":3},{"success":4,"breach":5},true,{"_id":6,"name":7,"title":8,"slug":9,"domain":10,"breachDate":11,"addedDate":12,"modifiedDate":13,"contentUpdatedAt":14,"source":15,"sourceUrl":16,"sourceUrls":17,"pwnCount":20,"affectedCount":20,"affectedCountStatus":21,"affectedCountLowerBound":22,"affectedCountUnit":23,"hasEnglishDescription":4,"severity":24,"dataClasses":25,"description":45,"seoTitle":46,"seoTitleEn":47,"seoDescription":46,"seoDescriptionEn":48,"logoUrl":49,"isVerified":4,"isSensitive":4,"isSpamList":50,"isMalware":50,"company":51},"68e3266eda11adda48825168","cyber-serve","CyberServe Data Breach","cyberserve","cyberserve.co.il","2021-10-29T00:00:00.000Z","2021-11-04T09:58:03.000Z","2026-07-02T12:26:55.059Z","2026-07-18T23:49:12.612Z","Third party breach","https:\u002F\u002Fwww.calcalistech.com\u002Fctech\u002Farticles\u002F0,7340,L-3921304,00.html",[16,18,19],"https:\u002F\u002Fwww.jpost.com\u002Fisrael-news\u002Firanian-hackers-breach-israeli-company-cyberserve-683529","https:\u002F\u002Fwww.securityweek.com\u002Fhackers-release-israeli-lgbtq-dating-site-details\u002F",1107034,"known",null,"unknown","Critical",[26,27,28,29,30,31,32,33,34,35,36,37,38,39,40,41,42,43,44],"Dates of birth","Drinking habits","Email addresses","Family structure","Genders","Geographic locations","HIV statuses","IP addresses","Names","Passwords","Personal health data","Phone numbers","Physical attributes","Private messages","Profile photos","Religions","Sexual orientations","Smoking habits","Usernames","\u003Cp>The CyberServe data breach is a highly sensitive incident associated with the Israeli-based hosting provider CyberServe being targeted by a ransomware attack in October 2021 and the leakage of data from various customer systems. The verified number of affected accounts for this record is 1,107,034. The incident exposed a wide range of personal, health, and relationship data, including information related to the LGBTQ dating service Atraf and the medical institution Machon Mor.\u003C\u002Fp>\n\u003Cp>This record should not be considered just an ordinary email and password leak. Verified data classes include dates of birth, drinking and smoking habits, family structure, gender, geographic location, HIV status, IP addresses, names, plaintext passwords, personal health data, phone numbers, physical characteristics, private messages, profile photos, religion, sexual orientation, and usernames. Some of these fields can have serious and lasting effects on individuals' safety, privacy, and social life.\u003C\u002Fp>\n\u003Ch2>Leaking Data Types and Risks\u003C\u002Fh2>\n\u003Cp>The CyberServe incident involves very broad data classes. Email addresses, usernames, IP addresses, and plain passwords create risks of account takeover and password reuse. Phone numbers, names, birth dates, and geographic location information can make targeted phishing and scam messages more convincing. Profile photos and physical characteristics can be used for personal identification, creating fake profiles, and social engineering.\u003C\u002Fp>\n\u003Cp>The most sensitive aspect of the incident is the presence of areas such as sexual orientation, HIV status, personal health data, private messages, religion, family structure, and habit information. These data can pose risks not only in terms of digital account security but also regarding a person's social environment, family relationships, professional life, and physical safety. Due to the context of an LGBTQ dating service, some users may face the risk of involuntary disclosure, targeted harassment, blackmail, or discrimination. Health data can lead to privacy consequences that cannot be changed or easily disclosed even years later.\u003C\u002Fp>\n\u003Ch2>Verified Scope and Boundaries\u003C\u002Fh2>\n\u003Cp>This record covers 1,107,034 affected accounts and the date of the incident is recorded as October 29, 2021. Since CyberServe provides hosting services to multiple clients, the incident should not be seen as a simple user table of a single application. Data classes from services related to dating, like Atraf, and health, like Machon Mor, are included under the same main incident. Therefore, the types of data are broad and it should not be assumed that the same fields exist in every account.\u003C\u002Fp>\n\u003Cp>Verified scope includes fields such as date of birth, drinking habits, email address, family structure, gender, geographic location, HIV status, IP address, name, password, personal health data, phone number, physical characteristics, private messages, profile photo, religion, sexual orientation, smoking habits, and username. In this record, payment card, bank account, or official ID number is not a verified data class. However, the existing data classes create an extremely high privacy impact independently of payment data.\u003C\u002Fp>\n\u003Ch2>User Groups at Risk\u003C\u002Fh2>\n\u003Cp>The people at the highest risk are users who have private areas such as profile information, messages, photos, sexual orientation, or HIV status on dating services like Atraf. For these users, the risk is not only phishing; offline consequences such as involuntary disclosure, blackmail, harassment, discrimination, and social pressure may also arise. For those associated with healthcare, the exposure of medical information and communication data is also important.\u003C\u002Fp>\n\u003Cp>Users who reuse the same password on other services are also at high risk due to accounts with exposed passwords. People with phone numbers, names, photos, and location information can be targeted with messages, calls, or social media communications that appear realistic. For users whose identity needs to remain hidden in their work or family circles, this leak should be considered critical for personal security. Therefore, action should not be limited to only a technical password change.\u003C\u002Fp>\n\u003Ch2>Urgent Measures to Be Taken\u003C\u002Fh2>\n\u003Cp>The user who sees a match in this record should first change all accounts where the same or a similar password is used. New passwords should be unique, long, and hard to guess. The email account should be protected with multi-factor authentication, and recent sessions, forwarding rules, and recovery options should be checked. Password cleanup should not be postponed because clear password data has been found.\u003C\u002Fp>\n\u003Cp>Due to the risk of sensitive data, users should be careful against communications themed around blackmail, threats, fake legal notices, health records, dating accounts, profile photos, or private messages. If such a message arrives, one should avoid opening links, making payments, or sharing verification codes without panicking. Security or support operations should only be conducted through known official channels. Users who feel a physical security risk should consider seeking help from trusted individuals or local support institutions.\u003C\u002Fp>\n\u003Ch2>Long-Term Security Strategies\u003C\u002Fh2>\n\u003Cp>The CyberServe incident shows that hosting provider breaches can simultaneously affect users across multiple customer systems. Users should regularly review what information they share on sensitive dating, health, or community services. The potential impact of leaks should be considered when sharing real names, clear photos, location, health status, sexual orientation, or family information on a profile. Unused accounts should be closed and unnecessary profile fields should be minimized.\u003C\u002Fp>\n\u003Cp>In the long term, a unique password for each service and strong email security are fundamental measures. However, in this case, the privacy risk is broader than just technical account security. Users may prefer separate email addresses for sensitive services, limited profile information, and more controlled photo sharing. From an institutional perspective, access segregation, encryption, logging, incident response, and data minimization controls at providers hosting customer systems are critically important.\u003C\u002Fp>\n\u003Ch2>Record Control and User Action\u003C\u002Fh2>\n\u003Cp>The presence of a match in this record indicates that the relevant email address is among the data sets seen in the CyberServe incident. The match should be evaluated considering that the incident involves multiple customer systems; data types may vary depending on the account and service. However, the record should be considered high priority because fields such as sexual orientation, HIV status, health data, private messages, and plaintext passwords are verified to be within scope.\u003C\u002Fp>\n\u003Cp>The user should immediately terminate the password reset, strengthen their email account, and be prepared against blackmail or phishing attempts related to private data. Profiles used in dating, health, or community services should be reviewed, unnecessary personal information should be minimized, and fake support messages should be verified through a separate channel. Even if this incident is from an earlier date, the risk can persist for a long time due to unchangeable or very sensitive information such as sexual orientation and health.\u003C\u002Fp>","","CyberServe Data Breach (1.1 Million Reported Records)","CyberServe Data Breach. 1.1 Million reported records were reported. Reported data: Dates of birth, Drinking habits, Email addresses. Review the scope, risks…","\u002Fuploads\u002Flogo\u002Fcyberserve_co_il.webp",false,{"name":52,"sector":53,"country":54,"website":10,"websiteArchiveUrl":46,"websiteStatus":46,"websiteCheckedAt":22},"CyberServe","Web hosting and internet services","Israel"]