[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fjb90ckvchmqw":3},{"success":4,"breach":5},true,{"_id":6,"name":7,"title":8,"slug":9,"domain":10,"breachDate":11,"addedDate":12,"modifiedDate":12,"contentUpdatedAt":13,"source":14,"sourceUrl":15,"sourceUrls":16,"pwnCount":19,"affectedCount":19,"affectedCountStatus":20,"affectedCountLowerBound":21,"affectedCountUnit":22,"hasEnglishDescription":4,"severity":23,"dataClasses":24,"description":30,"seoTitle":31,"seoTitleEn":32,"seoDescription":31,"seoDescriptionEn":33,"logoUrl":34,"isVerified":4,"isSensitive":35,"isSpamList":35,"isMalware":35,"company":36},"68e3266eda11adda488251c2","EyeEm","EyeEm Data Breach","eyeem","eyeem.com","2018-02-28T00:00:00.000Z","2019-02-16T07:17:45.000Z","2026-07-19T21:49:00.019Z","Database leak","https:\u002F\u002Fwww.theregister.com\u002F2019\u002F02\u002F11\u002F620_million_hacked_accounts_dark_web\u002F",[15,17,18],"https:\u002F\u002Fweb.archive.org\u002Fweb\u002F20180217220941id_\u002Fhttps:\u002F\u002Fwww.eyeem.com\u002Fimprint","https:\u002F\u002Fwww.eyeem.com\u002F",19611022,"known",null,"unknown","Critical",[25,26,27,28,29],"Bios","Email addresses","Names","Passwords","Usernames","\u003Cp>The \u003Cstrong>EyeEm data breach\u003C\u002Fstrong> affected 19,611,022 unique email addresses belonging to the photography community in February 2018.\u003C\u002Fp>\u003Ch2>Types of Exposed Data and Risks\u003C\u002Fh2>\u003Cp>The verified classes are email addresses, names, usernames, profile biographies and password hashes. The archive offered for sale was advertised as 22,360,765 account rows, but approximately three million reportedly had no email address. The reliable impact measure is therefore the \u003Cstrong>19,611,022 unique email addresses\u003C\u002Fstrong> identified after deduplication; the two figures must not be added or presented as the same measure. Every row cannot be assumed to contain all five fields. A name, username and biography can connect a person with their photography and make targeted phishing more convincing. Email addresses support account discovery, while password hashes can be used for offline guessing and attempts against services where credentials were reused. Payment card and bank account information are not among the verified classes, so this event should not be presented as a financial-data exposure.\u003C\u002Fp>\u003Ch2>Breach Timeline and Technical Details\u003C\u002Fh2>\u003Cp>Account information was reported stolen from EyeEm's servers in February 2018 and later offered for sale with other large datasets. The incident became public on 11 February 2019; EyeEm notified customers the next day and forced account passwords to be reset. The record's 28 February date represents an event known only to have occurred during that month, not proof of the exact intrusion day. Passwords in examined rows were described as SHA-1 hashes. Reliable evidence does not establish whether EyeEm used a per-password salt, so calling them “salted” or “unsalted” would be speculative. A SHA-1 output is not plaintext, but weak passwords may be recovered through offline guessing. The initial access method was not established publicly, so the event should not be attributed to a particular flaw, third party or employee action without evidence.\u003C\u002Fp>\u003Ch2>User Groups at Risk\u003C\u002Fh2>\u003Cp>People who created an EyeEm account before February 2018, registered with an email address, or placed a real name, username and biography on their profile form the main risk group. Photographers, visual creators and licensing professionals may receive convincing fraudulent offers because names, handles and creative profiles can be combined. An old account remains relevant: its email can identify accounts elsewhere, an old password pattern may help predict newer choices, and profile details can support believable messages. Abuse may extend beyond takeover to fake copyright notices, licensing enquiries, payment requests, portfolio-verification prompts or password resets seeking fresh information. Inclusion in the dataset does not prove that every account was abused or every hash recovered. Exposure, password recovery and confirmed account compromise are separate outcomes.\u003C\u002Fp>\u003Ch2>Immediate Steps to Take\u003C\u002Fh2>\u003Cp>EyeEm's forced reset in 2019 stopped the old password on that platform, but risk remains wherever the same or a similar password was reused. Identify those accounts and replace each reused credential with a \u003Cstrong>strong, unique password\u003C\u002Fstrong>; a password manager makes this easier to maintain. Enable multi-factor authentication on important services, beginning with email, and review recovery details and active sessions for changes you do not recognize. Treat EyeEm notices, photo-licensing proposals, copyright claims and portfolio offers carefully by checking the sender's real domain and link destination. Do not open unexpected attachments; sign in by typing the service address instead of following a message link. Remove unfamiliar mailbox forwarding rules, application passwords or recovery methods, end unknown sessions and review recent security activity.\u003C\u002Fp>\u003Ch2>Long-Term Security Strategies\u003C\u002Fh2>\u003Cp>The age of this incident does not make exposed identity data worthless. Email addresses and profile details can remain accurate for years, and old datasets may be combined with newer collections to build targeting profiles. Generate a different password for every service, enable breach and weak-password alerts in your password manager, and prefer an authenticator app or hardware key for multi-factor authentication. Separate email aliases can show where an address was shared and make suspicious mail easier to recognize. Limiting biographies to necessary information also reduces social-engineering risk; avoid publishing a personal address, phone number, birth date or routine location without a clear need. Review active sessions, connected apps and recovery settings regularly, and close accounts you no longer use. Verify alerts through the official app or an address you type directly rather than a link in the message.\u003C\u002Fp>\u003Ch2>Check Your Data\u003C\u002Fh2>\u003Cp>A matching email address means it appeared in the February 2018 EyeEm dataset. It does not prove that the account remains open, that a plaintext password is visible, or that the account was taken over. Distinguish the breach period from the February 2019 disclosure and ask whether the old password was reused elsewhere. If matched, secure your email first and then accounts that may have used the same or a similar password. No match is an absolute safety guarantee: you may have registered with another address, some rows lacked email, or another incident may not yet be verified. Combine periodic checks with password-manager alerts, multi-factor authentication and account-activity reviews. For suspicious messages, inspect the actual sender domain, link destination, urgency and requests for a password or payment together. This turns a historical EyeEm check into an ongoing security practice.\u003C\u002Fp>","","EyeEm Data Breach (19.6 Million Reported Records)","EyeEm Data Breach. 19.6 Million reported records were reported. Reported data: Bios, Email addresses, Names. Review the scope, risks, and protective steps.","\u002Fuploads\u002Flogo\u002Feyeem_com.webp",false,{"name":37,"sector":38,"country":39,"website":10,"websiteArchiveUrl":31,"websiteStatus":31,"websiteCheckedAt":21},"EyeEm Mobile GmbH","Technology","Germany"]