[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f1lx0k3q7w7a4d":3},{"success":4,"breach":5},true,{"_id":6,"name":7,"title":8,"slug":7,"domain":9,"breachDate":10,"addedDate":11,"modifiedDate":12,"contentUpdatedAt":13,"source":14,"sourceUrl":15,"sourceUrls":16,"pwnCount":19,"affectedCount":19,"affectedCountStatus":20,"affectedCountLowerBound":21,"affectedCountUnit":22,"hasEnglishDescription":4,"severity":23,"dataClasses":24,"description":31,"seoTitle":32,"seoTitleEn":33,"seoDescription":32,"seoDescriptionEn":34,"logoUrl":35,"isVerified":4,"isSensitive":36,"isSpamList":36,"isMalware":36,"company":37},"68e3266eda11adda488251af","eskimi","Eskimi Data Breach","eskimi.com","2020-09-25T00:00:00.000Z","2022-07-16T07:51:26.000Z","2026-07-02T12:26:55.059Z","2026-07-18T23:50:15.024Z","AdTech platform breach","https:\u002F\u002Fwww.obscureiq.com\u002Fcirculating-data-breach\u002Feskimi-2020-9w2\u002F",[15,17,18],"https:\u002F\u002Fwww.goincognito.co\u002Falert-1197620-breached-accounts-at-eskimi\u002F","https:\u002F\u002Fdatabreach.com\u002Fbreach\u002Feskimi.com-2020",1197620,"known",null,"unknown","Critical",[25,26,27,28,29,30],"Dates of birth","Email addresses","Genders","Geographic locations","Passwords","Usernames","\u003Cp>The Eskimi data breach is a large-scale account data leak affecting users of the AdTech platform and dates back to late 2020. From the perspective of the record system, the incident is recorded as the breach of September 25, 2020. The dataset contains approximately 26 million records, while the main number of users affected is 1,197,620 unique email addresses. This distinction is important; the total number of records should not be read as the number of individual people.\u003C\u002Fp>\n\u003Cp>The verified data categories are birth dates, email addresses, gender information, geographic locations, passwords, and usernames. It is stated that passwords are stored in unsalted MD5 hash form. MD5 without salt is considered weak for modern password storage standards; therefore, the risk is high for weak or reused passwords. Profile fields in the context of advertising technology can increase the user's risk of phishing and profile matching.\u003C\u002Fp>\n\u003Ch2>Leaked Data Types and Risks\u003C\u002Fh2>\n\u003Cp>When the email address, username, date of birth, gender, and geographic location in the old record are evaluated together, a meaningful picture about the user's profile emerges. In the context of advertising technology and user targeting, these fields can be used to prepare messages that appear personalized. The geographic location field does not necessarily mean the exact GPS coordinates for each user; it can also be in the context of a region, city, or more general location. Nevertheless, when combined with the email and username, the privacy risk increases.\u003C\u002Fp>\n\u003Cp>The password field is one of the most critical risks. An unsalted MD5 hash causes the same passwords to turn into the same hash value, making it easier for attackers to quickly try common password lists. A hash does not necessarily mean that the password is exposed in plain text; however, weak or reused passwords are more likely to be cracked. If a user has used the same password for email, social media, ad panels, or other services, this leak can turn into account takeover attempts.\u003C\u002Fp>\n\u003Ch2>Verified Scope and Boundaries\u003C\u002Fh2>\n\u003Cp>The verified main scope for this record is 1,197,620 unique email addresses. The total dataset has been reported as approximately 26 million records. These two numbers should not be confused; a person may have multiple profiles or event lines. The event date is recorded as September 25, 2020; the inclusion of the record in breach query systems in 2022 does not mean that the breach date is 2022.\u003C\u002Fp>\n\u003Cp>Verified data classes are date of birth, email, gender, geographic location, password, and username. Phone number, physical address, payment card, bank account, real name-surname, or advertising campaign budget are not among the verified data classes of this record. Location data should also not be described as precise or sensitive for each record. The correct description should explain profile fields and the risk of weakly hashed passwords together but in a limited manner.\u003C\u002Fp>\n\u003Ch2>User Groups at Risk\u003C\u002Fh2>\n\u003Cp>The highest risk group consists of users who reuse the password from their Eskimi account on other accounts. If the same email and password combination is used on an email account, social media, advertising tools, or business accounts, attackers may attempt automated logins. Birth date and gender information can be used as additional context in account recovery or targeted messages.\u003C\u002Fp>\n\u003Cp>Users associated with advertising technology, marketing, and publisher accounts should also be cautious. Geographical location and username can help estimate which market or region a person is active in. For those registering with a corporate email address, the risk may carry over to work accounts; fake ad panel alerts, budget notifications, campaign suspensions, or account verification messages may appear more convincing.\u003C\u002Fp>\n\u003Ch2>Urgent Measures to Be Taken\u003C\u002Fh2>\n\u003Cp>If your e-mail address appears in an old record, first check whether the password used on this account has been repeated on other accounts. If the same or a similar password has been used for e-mail, advertising panel, social media, work accounts, or other services, change it immediately. New passwords should be unique, long, and random; they should be stored with a password manager. Using the old password with minor changes does not provide sufficient security.\u003C\u002Fp>\n\u003Cp>Enable this protection on accounts that support two-step verification. Do not click directly on links in messages related to ad accounts, campaign budgets, payment notifications, account suspension, or security verification. If you need to check the account, manually type the relevant service’s address into the browser. Check unknown sessions, forwarding rules, and recovery settings in your email account.\u003C\u002Fp>\n\u003Ch2>Long-Term Security Strategies\u003C\u002Fh2>\n\u003Cp>The Eskimi incident shows that the leakage of profile data together with account identity information on AdTech platforms poses a permanent risk. Organizations should use unique passwords, multi-factor authentication, and role-based access for advertising and marketing accounts. On the password storage side, outdated methods such as unsalted MD5 should not be used; modern, salted, and slow hash algorithms should be preferred. Unnecessary profile fields should also be limited by data retention policies.\u003C\u002Fp>\n\u003Cp>On the user side, a long-term approach is to manage business and personal advertising\u002Fmarketing accounts with separate email addresses and to never reuse passwords. Profile fields such as geographic location, date of birth, and gender should not be shared unnecessarily because they are hard to change or personal. Corporate teams should implement strong authentication and regular access review processes on employees' advertising panel accounts.\u003C\u002Fp>\n\u003Ch2>Record Control and User Action\u003C\u002Fh2>\n\u003Cp>If your email address appears in this record, it means you match one of the 1,197,620 unique emails in the dataset of approximately 26 million rows. This does not mean that your phone, payment card, or physical address has been leaked; these fields are not included in the verified coverage. In contrast, the combination of email, username, date of birth, gender, location context, and unsalted MD5 password hash is serious for account security.\u003C\u002Fp>\n\u003Cp>The correct action is to immediately stop repeating passwords, enable two-factor authentication on important accounts, verify messages about advertising or account security through official channels, and check your email account. Past data breaches have shown that when profile data and weakly hashed password data are leaked together, it can keep both account takeover and targeted phishing risks alive for a long time.\u003C\u002Fp>","","Eskimi Data Breach (1.2 Million Reported Records)","Eskimi Data Breach. 1.2 Million reported records were reported. Reported data: Dates of birth, Email addresses, Genders. Review the scope, risks, and…","\u002Fuploads\u002Flogo\u002Feskimi_com.webp",false,{"name":38,"sector":39,"country":40,"website":9,"websiteArchiveUrl":32,"websiteStatus":32,"websiteCheckedAt":21},"Eskimi","AdTech","International"]