[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f3n1eour5r14i0":3},{"success":4,"breach":5},true,{"_id":6,"name":7,"title":8,"slug":9,"domain":10,"breachDate":11,"addedDate":12,"modifiedDate":12,"contentUpdatedAt":13,"source":14,"sourceUrl":15,"sourceUrls":16,"pwnCount":21,"affectedCount":21,"affectedCountStatus":22,"affectedCountLowerBound":23,"affectedCountUnit":24,"hasEnglishDescription":4,"severity":25,"dataClasses":26,"description":33,"seoTitle":34,"seoTitleEn":35,"seoDescription":34,"seoDescriptionEn":36,"logoUrl":37,"isVerified":4,"isSensitive":38,"isSpamList":38,"isMalware":38,"company":39},"68e3266eda11adda488251ae","Epik","Epik Data Breach","epik","epik.com","2021-09-13T00:00:00.000Z","2021-09-19T21:27:17.000Z","2026-07-20T04:49:22.996Z","Website hack","https:\u002F\u002Ftwitter.com\u002FEpikDotCom\u002Fstatus\u002F1439020408783654917",[15,17,18,19,20],"https:\u002F\u002Farstechnica.com\u002Finformation-technology\u002F2021\u002F09\u002Fanonymous-leaks-gigabytes-of-data-from-epik-web-host-of-gab-and-parler\u002F","https:\u002F\u002Farstechnica.com\u002Finformation-technology\u002F2021\u002F09\u002Fepik-data-breach-impacts-15-million-users-including-non-customers\u002F","https:\u002F\u002Fwww.epik.com\u002F","https:\u002F\u002Fwww.epik.com\u002Fwp-content\u002Fthemes\u002Fepik-redesign\u002Fsrc\u002Fimg\u002FEpikLogo.png",15003961,"known",null,"unknown","Critical",[27,28,29,30,31,32],"Email addresses","Names","Passwords","Phone numbers","Physical addresses","Purchases","\u003Cp>The September 13, 2021 \u003Cstrong>Epik data breach\u003C\u002Fstrong> affected 15,003,961 unique email addresses and associated account data.\u003C\u002Fp>\u003Ch2>Types of Exposed Data and Risks\u003C\u002Fh2>\u003Cp>The verified data set contained email addresses, names, phone numbers, physical addresses, purchase information, and passwords stored in various formats. “Various formats” does not mean every password used the same protection or that all passwords were plaintext; one algorithm has not been verified for every record. The archive was not limited to Epik customers. Because Epik systems retained WHOIS records, contact information belonging to domain owners who had never directly transacted with the company also appeared. Masked email variants used for domain privacy could be included in the count, so an address appearing in this incident does not prove that its owner was an Epik customer. Combining an email address, name, phone number, street address, and purchase context can support targeted phishing, fake support calls, and account-recovery abuse.\u003C\u002Fp>\u003Ch2>Breach Timeline and Technical Details\u003C\u002Fh2>\u003Cp>The canonical incident date is September 13, 2021. Unauthorized access led to the extraction of a broad archive belonging to domain registrar and web-hosting provider Epik; the publicly released package was reported to be about 180 GB, and the company later confirmed an unauthorized intrusion into its systems. Archive size is not the same measure as the number of affected people: the count is based on \u003Cstrong>15,003,961 unique email addresses\u003C\u002Fstrong>. Customer account material alongside retained WHOIS records explains why the scope cannot be limited to active customers. Some WHOIS entries could contain historical ownership details, preventing a direct inference from an email match to present-day domain ownership. The initial access path, precise dwell time, and protection format used for every password were not conclusively documented for all accounts, so those details should not be guessed.\u003C\u002Fp>\u003Ch2>User Groups at Risk\u003C\u002Fh2>\u003Cp>The most directly exposed group includes customers, former customers, domain administrators, and hosting users who had an Epik account in or before September 2021. A second group consists of domain owners and organization contacts whose information appeared in retained WHOIS records despite having no contractual relationship with Epik. People using privacy or proxy registration services may also appear through masked addresses, forwarding addresses, or historical records. For employees managing business domains, the risk extends beyond a personal account: criminals can combine a name, phone number, address, and purchase context to create convincing domain-transfer, DNS-change, or false-invoice requests. Appearing in the incident therefore does not prove current Epik use, but it can still make targeted fraud more credible.\u003C\u002Fp>\u003Ch2>Immediate Steps to Take\u003C\u002Fh2>\u003Cp>If you have an Epik account, navigate directly to the official site and change its password; then replace the same or similar password on every other account. \u003Cstrong>Password reuse\u003C\u002Fstrong> can allow an old breach to fuel automated login attempts against email, cloud storage, social media, or financial services years later. Create a long, unique password for each service, use a password manager, and enable multi-factor authentication on supported accounts. Domain owners should review registrar lock status, transfer authorization, recovery details, nameservers, and DNS records. Independently sign in before approving an unexpected reset, domain transfer, or contact change. Purchase information is among the documented exposed categories, but payment-card exposure has not been verified; still review unexpected charges and fraudulent renewal invoices. Do not follow links in suspension messages, and never disclose a one-time code.\u003C\u002Fp>\u003Ch2>Long-Term Security Strategies\u003C\u002Fh2>\u003Cp>Durable protection requires an account and domain inventory rather than a one-time password change. Standardize unique passwords across personal and organizational accounts, prefer app- or hardware-key-based multi-factor authentication, and review recovery channels on a schedule. For critical domains, use registry lock, change approval, or multi-administrator workflows when supported. Alerts for DNS, nameserver, registrant-contact, and renewal changes can expose a domain-hijacking attempt early. WHOIS privacy can reduce public visibility, but it cannot retrieve records collected in the past, so treat old addresses and phone numbers as potentially useful to a fraudster. Organizations should use role-based mailboxes for domain administration, restrict access according to job need, and promptly remove access when personnel leave. Ongoing breach monitoring and review of change logs reduce dependence on a single defensive control.\u003C\u002Fp>\u003Ch2>Check Your Data\u003C\u002Fh2>\u003Cp>When checking whether your email address is associated with the Epik incident through LeakData, interpret the result in context. A match means the address appears in the verified data set; it does not show that the person purchased an Epik service, remains a customer, or currently owns an associated domain. If you receive a match, inventory Epik, registrar, hosting, and administrative accounts created with that address, then review password uniqueness, multi-factor authentication, recovery details, and domain locks. No match is not an absolute guarantee because the data set can be incomplete, a different address may have been used, or more information may emerge. Continue account-activity alerts and periodic monitoring. For incident-themed messages, inspect the sender domain and destination link rather than trusting the display name, and verify suspicious requests through an independently opened official support channel.\u003C\u002Fp>","","Epik Data Breach (15 Million Reported Records)","Epik Data Breach. 15 Million reported records were reported. Reported data: Email addresses, Names, Passwords. Review the scope, risks, and protective steps.","\u002Fuploads\u002Flogo\u002Fepik_com.webp",false,{"name":7,"sector":40,"country":41,"website":10,"websiteArchiveUrl":34,"websiteStatus":34,"websiteCheckedAt":23},"Domain registrar and web hosting","United States"]