[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f1mvh7z5ojvxrh":3},{"success":4,"breach":5},true,{"_id":6,"name":7,"title":8,"slug":9,"domain":10,"breachDate":11,"addedDate":12,"modifiedDate":13,"contentUpdatedAt":14,"source":15,"sourceUrl":16,"sourceUrls":17,"pwnCount":20,"affectedCount":20,"affectedCountStatus":21,"affectedCountLowerBound":22,"affectedCountUnit":23,"hasEnglishDescription":4,"severity":24,"dataClasses":25,"description":29,"seoTitle":30,"seoTitleEn":31,"seoDescription":30,"seoDescriptionEn":32,"logoUrl":33,"isVerified":4,"isSensitive":34,"isSpamList":34,"isMalware":34,"company":35},"68e3266eda11adda4882516a","da-font","DaFont Data Breach","dafont","dafont.com","2017-05-16T00:00:00.000Z","2017-05-18T20:05:28.000Z","2026-07-02T12:26:55.059Z","2026-07-18T23:49:16.624Z","Third party breach","https:\u002F\u002Fwww.tripwire.com\u002Fstate-of-security\u002F600k-user-accounts-exposed-dafont-database-theft",[16,18,19],"https:\u002F\u002Fwww.bitdefender.com\u002Fen-us\u002Fblog\u002Fhotforsecurity\u002Fdafont-com-hacked-entire-database-leaked-online","https:\u002F\u002Fdatabreach.com\u002Fbreach\u002Fdafont.com-2017",637340,"known",null,"unknown","High",[26,27,28],"Email addresses","Passwords","Usernames","\u003Cp>The DaFont data breach is related to the account data leak that occurred on the site dafont.com, which is used as a free and shared font archive, in May 2017. The number of affected accounts verified for this record is 637,340. In the incident, usernames, email addresses, and password hashes stored in unsalted MD5 format were exposed. The breach has been reported to be associated with an SQL injection type vulnerability.\u003C\u002Fp>\n\u003Cp>Creative sites like DaFont, used for design and font downloading purposes, are considered low risk by most users. However, if the email and password combinations used on such platforms are repeated on other accounts, an old font archive account can pose a risk for current email, social media, shopping, forum, or work accounts. Since the use of unsalted MD5 hashes is weak according to modern security standards, it is easier to guess weak passwords.\u003C\u002Fp>\n\u003Ch2>Leaking Data Types and Risks\u003C\u002Fh2>\n\u003Cp>The verified data classes are email addresses, usernames, and passwords. The password field is in unsalted MD5 hash format; this does not mean that the password is published in a directly readable form. Nevertheless, since MD5 is a fast and weak hashing method, especially simple or previously leaked passwords can be easily guessed by attackers. The absence of a salt also facilitates the association of accounts using the same password with the same hash values.\u003C\u002Fp>\n\u003Cp>When an email address and username are found together, it may be possible to match users with other creative platforms, forums, design communities, or social media profiles. A DaFont account alone may not seem highly valuable; however, if the same password has been used on other services, the risk increases. Targeted fake font, license, download link, or account alert messages can become convincing, especially for designers, agency employees, or people who use the same email address in work tools.\u003C\u002Fp>\n\u003Ch2>Verified Scope and Boundaries\u003C\u002Fh2>\n\u003Cp>This record covers 637,340 affected accounts and is recorded as having occurred on May 16, 2017. Although some technical reports mention higher raw database row counts, the value used in this record represents the verified account scope. The main data classes of the incident are email address, username, and unsalted MD5 password hash. The site later stated that it had strengthened the password storage structure and enforced password changes for users.\u003C\u002Fp>\n\u003Cp>In this record, IP address, phone number, physical address, payment card, bank account, date of birth, real name, or private message content is not considered a verified data class. The incident should be evaluated as limited to DaFont user account data. A match indicates that the related email address is present in the DaFont dataset; it does not mean that the user's font files, payment information, or device were affected.\u003C\u002Fp>\n\u003Ch2>User Groups at Risk\u003C\u002Fh2>\n\u003Cp>The people at the highest risk are users who reuse the password they use for their DaFont account on other accounts as well. Passwords used on old and low-priority accounts are often forgotten; however, attackers can use these passwords in automated login attempts. If the email and username are the same, different design communities or social media accounts can also be linked.\u003C\u002Fp>\n\u003Cp>Designers, agency employees, font producers, and users active in creative communities are at a higher risk of targeted phishing. Fake font licenses, copyright notices, download packages, design files, or account security messages may appear realistic. For users registered with a work email, this risk can also extend to corporate security. Therefore, not only the DaFont account but all accounts using the same email and password family should be considered.\u003C\u002Fp>\n\u003Ch2>Urgent Measures to Be Taken\u003C\u002Fh2>\n\u003Cp>A user who sees a match in this record should change the password used on their DaFont account and all accounts where the same or a similar password is used. New passwords should be unique, long, and difficult to guess. The email account should be protected as a priority, multi-factor authentication should be enabled, and recent sessions should be checked. Variations of the old password maintained with small changes should also not be considered secure.\u003C\u002Fp>\n\u003Cp>Unexpected messages themed around font download, license violation, copyright notice, free package, design file, or account verification should be noted. The domain name and sender should be verified before opening links and attachments. A sender who knows the username or an old DaFont membership is not trustworthy. Passwords, verification codes, email access, or account recovery information should not be shared with third parties.\u003C\u002Fp>\n\u003Ch2>Long-Term Security Strategies\u003C\u002Fh2>\n\u003Cp>The DaFont incident shows that even creative community accounts considered low-priority are important in terms of password security. Users should use unique passwords for every forum, download site, design community, and work tool. Using a password manager makes it easier to see where old passwords are reused and to generate strong passwords. Unused accounts should be closed or, at the very least, updated with a unique password.\u003C\u002Fp>\n\u003Cp>In the long term, it is also useful to separate usernames and email addresses. When the same username and email combination is repeated across different design communities, profiles can be easily matched. Since file and font links used in creative work may contain malware or phishing, users should only download from trusted sources and verify unexpected license or copyright messages through a separate channel.\u003C\u002Fp>\n\u003Ch2>Record Control and User Action\u003C\u002Fh2>\n\u003Cp>A match in this record indicates that the relevant email address is among the accounts seen in the May 2017 DaFont data breach. A match does not indicate that the event occurred in the current year; in this record, the event date is May 16, 2017. The verified scope is limited to the email address, username, and unsalted MD5 password hash.\u003C\u002Fp>\n\u003Cp>The user should first change all accounts where the same password is used, protect their email account with two-factor authentication, and review old username\u002Fpassword combinations used on creative platforms. Even if the DaFont account is no longer actively used, the risk continues if the same password was used on other services. The unsalted MD5 hash format, combined with weak password choices, can pose a long-term account security risk.\u003C\u002Fp>","","DaFont Data Breach (637.3 Thousand Reported Records)","DaFont Data Breach. 637.3 Thousand reported records were reported. Reported data: Email addresses, Passwords, Usernames. Review the scope, risks, and…","\u002Fuploads\u002Flogo\u002Fdafont_com.webp",false,{"name":36,"sector":37,"country":30,"website":10,"websiteArchiveUrl":30,"websiteStatus":30,"websiteCheckedAt":22},"DaFont","Font sharing website"]