[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f30a8hfxob952":3},{"success":4,"breach":5},true,{"_id":6,"name":7,"title":8,"slug":7,"domain":9,"breachDate":10,"addedDate":11,"modifiedDate":12,"contentUpdatedAt":13,"source":14,"sourceUrl":15,"sourceUrls":16,"pwnCount":17,"affectedCount":17,"affectedCountStatus":18,"affectedCountLowerBound":19,"affectedCountUnit":20,"hasEnglishDescription":4,"severity":21,"dataClasses":22,"description":28,"seoTitle":15,"seoTitleEn":29,"seoDescription":15,"seoDescriptionEn":30,"logoUrl":31,"isVerified":4,"isSensitive":4,"isSpamList":32,"isMalware":32,"company":33},"68e3266eda11adda488251d1","famm","Famm Data Breach","famm.us","2020-10-08T00:00:00.000Z","2022-07-16T09:57:48.000Z","2026-07-02T12:26:55.059Z","2026-07-18T23:50:36.696Z","Family photo service account data breach","",[],535240,"known",null,"unknown","High",[23,24,25,26,27],"Dates of birth","Email addresses","Genders","Names","Passwords","\u003Cp>The Famm data breach is a confirmed incident affecting the Japanese family photo service on October 8, 2020. The record covers 535,240 unique email accounts; in incident reports, the total number of customer records is mentioned as approximately 1.3 million. Verified types of data include birth dates, email addresses, gender information, names, and passwords. Although passwords were stored as SHA-256 hashes, this algorithm alone does not provide sufficient security for modern password protection; weak or reused passwords pose a risk. Due to the context of the family photo service, users have high expectations of privacy, but it has not been confirmed that photo content was leaked in this breach. The risks are related to account security, identity matching, and family service-themed phishing.\u003C\u002Fp>\n\u003Ch2>Leaked Data Types and Risks\u003C\u002Fh2>\n\u003Cp>The data types listed in this record are the fields Dates of birth, Email addresses, Genders, Names, and Passwords. When email, name, and date of birth are found together, attackers can create account alerts or family service notifications that appear personal. Gender information and date of birth can be used for identity matching and to make targeted messages more convincing. The password field is in SHA-256 hash form; it does not mean plaintext password, but weak passwords or passwords matching other leaks can be cracked. This record should not be presented as a phone, physical address, payment card, or photo content leak. However, in the context of a family photo service, it can increase user trust in fake album sharing, fake account recovery, or fake membership renewal messages.\u003C\u002Fp>\n\u003Ch2>Verified Scope and Boundaries\u003C\u002Fh2>\n\u003Cp>The verified primary metric is 535,240 unique email accounts. The total number of customer records may be higher; this number is not the same as the number of unique emails. Data classes are limited to date of birth, email, gender, name, and password hashes. Photos, album contents, private messages of family members, phone numbers, physical addresses, payment cards, or official identification information are not among the verified fields of this record. Being a Japanese family photo service increases the privacy impact of the incident, but the unverified media content claim should not be added. Specifying the password hashes as SHA-256 should not give users a false sense of security; if passwords are reused, the risk continues. Therefore, the record should be kept with a sensitive data label, but its scope should be limited to verified fields.\u003C\u002Fp>\n\u003Ch2>User Groups at Risk\u003C\u002Fh2>\n\u003Cp>The main group at risk consists of families who have opened a Famm account, parents, individuals who have used photo sharing or printing services, and users who reuse the same password across other family, photo, email, or social media accounts. People with birth date and name information can be targeted with fake birthday notifications, fake album invitations, or fake account recovery messages. Parents and family members may respond more quickly to emotionally charged messages due to the context of child or family photo services. The risk increases if the same email address also appears in other family, e-commerce, or social media leaks. In accounts with password reuse, attackers may first take over the email account and then attempt to access photo, cloud, and social media services. Even if the photo content is not verified, the service context is valuable for social engineering.\u003C\u002Fp>\n\u003Ch2>Urgent Measures to Be Taken\u003C\u002Fh2>\n\u003Cp>If your email address appears in this record, do not consider the password you used on your Famm account secure anymore. Set unique passwords for email, cloud, photo, social media, shopping, and family sharing accounts where you use the same or similar password. Enable multi-factor authentication on services that offer it. Before clicking on links in unexpected album sharing, account recovery, family invitation, membership renewal, or photo printing campaign messages, access your account directly from the known web address. Do not trust messages that know your birth date or name too much; this information could have come from a leak. Check password reset alerts and unknown sessions on your email account. If there is a shared email with family members, their account security should also be reviewed.\u003C\u002Fp>\n\u003Ch2>Long-Term Security Strategies\u003C\u002Fh2>\n\u003Cp>Accounts used in family and photo services carry higher privacy expectations than ordinary memberships. Users should use unique passwords for photos, family sharing, and cloud services, prefer a password manager, and close unused old accounts. Fields such as birth date, family name, and children’s information should not be shared on publicly accessible profiles. When sharing albums with family members, it should be regularly checked who the invitation links are accessible to. On the platform side, password hashes should be protected with strong and up-to-date methods, old hash formats should be upgraded, and account recovery processes should be monitored against abuse. Users should regularly check whether the same email address appears in other photo, family, e-commerce, or social media leaks.\u003C\u002Fp>\n\u003Ch2>Record Control and User Action\u003C\u002Fh2>\n\u003Cp>LeakData check shows whether your email address appears in the Famm leak. A positive result does not indicate that verified data classes include photo content, payment card, or physical address; the verified risk is the misuse of birth date, email, gender, name, and SHA-256 password hashes. User actions include changing reused passwords, prioritizing the email account, enabling multi-factor authentication on family and photo services, and verifying fake album or membership messages. If the same email appears in other leaks, the risk increases; attackers can combine the family service context with phone, address, or social profile information from other sources to create more convincing messages.\u003C\u002Fp>","Famm Data Breach (535.2 Thousand Reported Records)","Famm Data Breach. 535.2 Thousand reported records were reported. Reported data: Dates of birth, Email addresses, Genders. Review the scope, risks, and…","\u002Fuploads\u002Flogo\u002Ffamm_us.webp",false,{"name":34,"sector":35,"country":36,"website":9,"websiteArchiveUrl":15,"websiteStatus":15,"websiteCheckedAt":19},"Famm","Photo Sharing","Japan"]