[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f2bdfff9h6d7sa":3},{"success":4,"breach":5},true,{"_id":6,"name":7,"title":8,"slug":9,"domain":10,"breachDate":11,"addedDate":12,"modifiedDate":12,"contentUpdatedAt":13,"source":14,"sourceUrl":15,"sourceUrls":16,"pwnCount":17,"affectedCount":17,"affectedCountStatus":18,"affectedCountLowerBound":19,"affectedCountUnit":20,"hasEnglishDescription":4,"severity":21,"dataClasses":22,"description":30,"seoTitle":31,"seoTitleEn":32,"seoDescription":31,"seoDescriptionEn":33,"logoUrl":34,"isVerified":4,"isSensitive":35,"isSpamList":35,"isMalware":35,"company":36},"68e3266eda11adda488251b9","Evite","Evite Data Breach","evite","evite.com","2013-08-11T00:00:00.000Z","2019-07-14T14:51:51.000Z","2026-07-18T23:50:23.676Z","Verified breach record","https:\u002F\u002Fwww.evite.com\u002Fsecurity\u002Fupdate?lctid=1800182&usource=lc",[15],100985047,"known",null,"unknown","Critical",[23,24,25,26,27,28,29],"Dates of birth","Email addresses","Genders","Names","Passwords","Phone numbers","Physical addresses","\u003Cp>Evite is an online invitation and event planning service. In 2019, the company announced that there had been unauthorized access to a database of archival data containing user information from 2013 and earlier. The verified domain consists of 100,985,047 unique email addresses. A significant portion of the people affected by this incident are invitation recipients; for service members, the verified scope also includes fields such as name, phone number, physical address, date of birth, gender, and plain text password.\u003C\u002Fp>\u003Cp>The Evite incident is not just a risk to email visibility. The password field being in plain text increases the risk of account takeover if the same password is reused on other sites. Identity fields such as phone number, address, date of birth, and name can make fake invitations, deliveries, payments, events, or support messages more convincing.\u003C\u002Fp>\u003Ch2>Leaked Data Types and Risks\u003C\u002Fh2>\u003Cp>The verified data classes in the Evite dataset are birth dates, email addresses, gender information, name-surname information, passwords, phone numbers, and physical addresses. Email addresses can be used for targeted phishing, password reset traps, and account matching. Name-surname and phone information personalize fake customer service, fake delivery, or event notification messages. Physical addresses and birth dates increase the risk of guessing authentication questions, profile completion, and social engineering.\u003C\u002Fp>\u003Cp>The exposure of passwords in plain text is the most critical part of the incident. A plain text password allows the attacker to try the same value on other services without needing a password cracking process. If the same password is reused on email accounts, social media, shopping, work accounts, or cloud storage, the risk is not limited to just the Evite account.\u003C\u002Fp>\u003Ch2>Verified Scope and Boundaries\u003C\u002Fh2>\u003Cp>The breach date for Evite should be considered as August 11, 2013, the record addition date as July 14, 2019, and the number of affected accounts as 100,985,047. The incident is associated with unauthorized access to an archival database containing data from 2013 and earlier. Therefore, although the incident was disclosed to the public in 2019, the source date of the user data is older.\u003C\u002Fp>\u003Cp>One should not go beyond verified data classes. The supported scope for Evite is limited to date of birth, email address, gender information, first and last name, password, phone number, and physical address fields. Fields outside of these seven classes should not be presented as definite leak information. The password field is verified; details outside the scope should not be added as definite information to the risk narrative.\u003C\u002Fp>\u003Ch2>User Groups at Risk\u003C\u002Fh2>\u003Cp>People who have an Evite account, users who have received an invitation in the past, people who have been using the same email address for many years, and account owners who reuse the same password across multiple services are at higher risk. Data coming from an old archive does not mean the risk is over; because reused passwords can be tried on different sites even years later.\u003C\u002Fp>\u003Cp>Users with phone numbers and address information should be more cautious against fake delivery, event, donation, invitation, or support messages. Fields such as date of birth and gender can make the profile seem more realistic, causing scam messages to appear trustworthy. For individuals using corporate email, the risk can also extend to messages arriving under the pretext of fake meeting invitations or business connections.\u003C\u002Fp>\u003Ch2>Urgent Measures to Be Taken\u003C\u002Fh2>\u003Cp>Users who have been matched with Evite should change their passwords on all accounts where they use the same or similar password. Email accounts, banking and payment services, social media, shopping sites, cloud storage, and work accounts should be prioritized. New passwords should be unique and long; they should be stored with a password manager if possible.\u003C\u002Fp>\u003Cp>Two-factor authentication should be enabled on all important accounts that support it, recent sessions and connected devices should be checked, and unrecognized sessions should be closed. Unexpected calls, deliveries, invoices, invitations, events, or support messages coming with phone, address, and date of birth information should be verified through a separate channel. The risk continues unless the password change encompasses all accounts where the old password was reused.\u003C\u002Fp>\u003Ch2>Long-Term Security Strategies\u003C\u002Fh2>\u003Cp>In the long term, using a unique password for each account, a password manager, and two-step verification are basic defenses. Even if old invitation or social planning accounts are forgotten, if the passwords used on these accounts were reused on other services, they can turn into a valid trial list for attackers. Users should review their old accounts, close accounts that are not necessary, and keep recovery information up to date for critical accounts.\u003C\u002Fp>\u003Cp>The exposure of personal communication and address information should be monitored not only from the perspective of technical account security but also in terms of social engineering. Users should check the sender before opening links in messages themed around invitations, events, donations, deliveries, or reservations; organizations should also inform their employees that convincing messages can be created using personal information from previous data breaches.\u003C\u002Fp>\u003Ch2>Record Control and User Action\u003C\u002Fh2>\u003Cp>LeakData check shows whether the queried email address is present in the Evite data set. A positive result indicates that the email address is included in this data set and that the verified data fields for the relevant user should be considered in the risk assessment. This result does not prove that all fields are fully available for each user; however, it is a sufficient warning for protective measures due to the risk of password and identity data.\u003C\u002Fp>\u003Cp>A negative result only means that no match was found in this dataset; it does not eliminate the possibility of appearing in other data breaches. Users who receive a positive result should reset their password, enable two-factor authentication, review old sessions, and be more cautious about targeted phishing messages received via phone or address information.\u003C\u002Fp>","","Evite Data Breach (101 Million Reported Records)","Evite Data Breach. 101 Million reported records were reported. Reported data: Dates of birth, Email addresses, Genders. Review the scope, risks, and…","\u002Fuploads\u002Flogo\u002Fevite_com.webp",false,{"name":7,"sector":37,"country":38,"website":10,"websiteArchiveUrl":31,"websiteStatus":31,"websiteCheckedAt":19},"Online invitations","United States"]