[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f3csqbph2svc6u":3},{"success":4,"breach":5},true,{"_id":6,"name":7,"title":8,"slug":9,"domain":10,"breachDate":11,"addedDate":12,"modifiedDate":12,"contentUpdatedAt":13,"source":14,"sourceUrl":15,"sourceUrls":16,"pwnCount":21,"affectedCount":21,"affectedCountStatus":22,"affectedCountLowerBound":23,"affectedCountUnit":24,"hasEnglishDescription":4,"severity":25,"dataClasses":26,"description":32,"seoTitle":33,"seoTitleEn":34,"seoDescription":33,"seoDescriptionEn":35,"logoUrl":36,"isVerified":4,"isSensitive":37,"isSpamList":37,"isMalware":37,"company":38},"68e3266eda11adda48825183","Disqus","Disqus Data Breach","disqus","disqus.com","2012-07-01T00:00:00.000Z","2017-10-06T23:03:51.000Z","2026-07-19T23:50:59.051Z","Database leak","https:\u002F\u002Fblog.disqus.com\u002Fsecurity-alert-user-info-breach",[15,17,18,19,20],"https:\u002F\u002Fweb.archive.org\u002Fweb\u002F20171006233027\u002Fhttps:\u002F\u002Fblog.disqus.com\u002Fsecurity-alert-user-info-breach","https:\u002F\u002Fwww.troyhunt.com\u002Fdisqus-demonstrates-how-to-do-data-breach-disclosure-right\u002F","https:\u002F\u002Fcyberscoop.com\u002Fdisqus-breach-2012-troy-hunt\u002F","https:\u002F\u002Fwptavern.com\u002Fdisqus-data-breach-affects-17-5-million-accounts",17551044,"known",null,"unknown","Critical",[27,28,29,30,31],"Email addresses","Usernames","Passwords","Registration dates","Last activity dates","\u003Cp>The Disqus data breach affected 17,551,044 accounts from July 2012 and exposed emails, usernames and password hashes.\u003C\u002Fp>\u003Ch2>Types of Exposed Data and Risks\u003C\u002Fh2>\u003Cp>The exposed database snapshot contained email addresses, Disqus usernames, sign-up dates and last-login dates in plain text. The confirmed impact count is \u003Cstrong>17,551,044 accounts associated with unique email addresses\u003C\u002Fstrong>. About one-third of the accounts included salted SHA-1 password hashes rather than plaintext passwords; the “Passwords” data class therefore refers to those hash values, not readable credentials. Users who signed in through a social authentication provider had references to those external accounts instead of a Disqus password. SHA-1 and salting do not reveal a password directly, but they cannot fully protect short or common choices from offline guessing. Combining an email address, username and activity dates can support targeted phishing, spam, historical account correlation and credential-stuffing attacks against unrelated services. Payment or card information has not been verified within the scope of this incident.\u003C\u002Fp>\u003Ch2>Breach Timeline and Technical Details\u003C\u002Fh2>\u003Cp>The exposed snapshot came from the 2012 user database, included information dating back to 2007 and contained no data newer than July 2012. The record therefore uses 1 July 2012 as a month-level incident date; reliable public evidence does not establish the exact day of access or the technical entry method. Disqus learned of the event years later when an independent researcher reported the dataset on 5 October 2017. The company obtained and began validating the data that day; on 6 October it reset passwords for accounts whose hashes appeared, contacted affected users and issued its public notice. Disqus said it had moved from SHA-1 to the stronger bcrypt password-hashing algorithm at the end of 2012. No evidence of breach-related unauthorized logins had been identified at disclosure, but the possibility of offline recovery made protection against password reuse necessary.\u003C\u002Fp>\u003Ch2>User Groups at Risk\u003C\u002Fh2>\u003Cp>The highest-risk group consists of people who registered directly with an email address and password in or before 2012 and reused the same or a similar password elsewhere. Salted SHA-1 hashes in the approximately one-third subset are especially vulnerable when passwords were short or based on common words. If a password is recovered, attackers can try it against email, social media, forum or shopping accounts. \u003Cstrong>Passwords belonging to external social sign-in providers were not in the snapshot\u003C\u002Fstrong>, although an email address, username and account reference may still have been exposed. Sign-up and last-login dates can help an attacker distinguish active accounts from abandoned ones and make a message appear more convincing. People who later changed the password and used unique credentials everywhere face less takeover risk, but phishing aimed at an older email address can remain effective.\u003C\u002Fp>\u003Ch2>Immediate Steps to Take\u003C\u002Fh2>\u003Cp>If the Disqus password you used in 2012 still exists on another service, replace every reused copy with a long, unique credential. Disqus reset affected passwords in 2017, but that action could not change copies on unrelated sites. Prioritize your primary email account, password manager, social networks and services holding a saved payment method. Enable multi-factor authentication on email and other critical accounts, then review active sessions, recovery addresses and recognized devices. Do not trust a message merely because it cites an old Disqus comment, username or registration date. Instead of following links in messages claiming to offer password resets, account verification or comment removal, navigate to the service’s official address independently. Never disclose a one-time authentication code, current password or password-manager master password through a message or call.\u003C\u002Fp>\u003Ch2>Long-Term Security Strategies\u003C\u002Fh2>\u003Cp>A password manager that generates a random, unique password for every service prevents recovery of one historical hash from spreading to other accounts. Keep multi-factor authentication permanently enabled on critical services and store recovery codes safely offline. Close unused commenting, forum and social accounts or minimize profile information left in them because forgotten accounts can support identity correlation. \u003Cstrong>Do not treat a 2012 breach as harmless merely because it is old\u003C\u002Fstrong>; its value persists when the same password or email relationship remains in use today. Monitor unexpected sign-in and password-reset alerts, review email-forwarding rules periodically and avoid reusing easily researched answers to security questions. Assume older usernames can be linked to public profiles and apply additional verification to messages built around those historical details.\u003C\u002Fp>\u003Ch2>Check Your Data\u003C\u002Fh2>\u003Cp>Use the secure search field on this page to check every current and historical email address you used with Disqus. A match means the address is one of the 17,551,044 unique emails in the verified database snapshot; it does not prove that the password was recovered or the account was taken over. If you receive a match, identify where the 2012-era password was reused and remove every surviving copy. No result is an absolute guarantee because a differently written address, a record outside this dataset or another breach may still exist. Never enter a password, social sign-in credential or authentication code into a breach search. Rechecking older addresses periodically can reveal newly published breach records early and gives you time to strengthen accounts before stolen data is misused.\u003C\u002Fp>","","Disqus Data Breach (17.6 Million Reported Records)","Disqus Data Breach. 17.6 Million reported records were reported. Reported data: Email addresses, Usernames, Passwords. Review the scope, risks, and protective…","\u002Fuploads\u002Flogo\u002Fdisqus_com.webp",false,{"name":7,"sector":39,"country":40,"website":10,"websiteArchiveUrl":33,"websiteStatus":33,"websiteCheckedAt":23},"Online commenting platform","United States"]