[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f3rpzimllarp1b":3},{"success":4,"breach":5},true,{"_id":6,"name":7,"title":8,"slug":7,"domain":9,"breachDate":10,"addedDate":11,"modifiedDate":12,"contentUpdatedAt":12,"source":13,"sourceUrl":14,"sourceUrls":15,"pwnCount":17,"affectedCount":17,"affectedCountStatus":18,"affectedCountLowerBound":19,"affectedCountUnit":20,"hasEnglishDescription":4,"severity":21,"dataClasses":22,"description":27,"seoTitle":28,"seoTitleEn":29,"seoDescription":28,"seoDescriptionEn":30,"logoUrl":31,"isVerified":4,"isSensitive":32,"isSpamList":32,"isMalware":32,"company":33},"68e3266eda11adda488251f6","gett","Ge.tt Data Breach","ge.tt","2017-05-04T00:00:00.000Z","2021-02-16T06:22:20.000Z","2026-07-29T11:40:53.262Z","Third party breach","https:\u002F\u002Fwww.zdnet.com\u002Farticle\u002F127-million-user-records-from-8-companies-put-up-for-sale-on-the-dark-web\u002F",[14,16],"https:\u002F\u002Fstartupstash.com\u002Fge-tt-alternatives\u002F",2481121,"known",null,"unknown","Critical",[23,24,25,26],"Email addresses","Names","Passwords","Social media profiles","\u003Cp>The Ge.tt data breach is a confirmed incident from May 2017 affecting accounts using the file-sharing platform. The confirmed scope is 2,481,121 unique email records. The affected data groups are email addresses, names, social media profile IDs, and SHA-256 password hashes. The incident data was later seen within a larger archive offered for sale alongside datasets belonging to different companies; however, these records represent only the verified user scope associated with Ge.tt. File contents, private file links, payment cards, phone numbers, physical addresses, government IDs, or plaintext passwords are not among the verified data types for this incident. The risk should be assessed as password reuse abuse, social profile matching, and phishing attempts via the file-sharing account.\u003C\u002Fp>\n\u003Ch2>Leaking Data Types and Risks\u003C\u002Fh2>\n\u003Cp>This breach included names, email addresses, social media profile IDs, and SHA-256 password hashes. SHA-256 hashes do not mean plaintext passwords; however, they are not by themselves considered the strongest current method for storing passwords. If a password is short, predictable, or reused on other accounts, attackers can target different services through hash cracking and automated login attempts. The risk increases if the same password is used for email, cloud storage, social media, or file-sharing accounts.\u003C\u002Fp>\n\u003Cp>Social media profile identities are also important in terms of profile matching. When the email address and name information are combined with social profile links, the user's identity on different platforms can be associated more easily. Fake sharing links coming from file sharing services, security alerts, or file download notifications may appear more convincing. Therefore, the user should be aware not only of password risks but also of link- and file-themed phishing risks.\u003C\u002Fp>\n\u003Ch2>Verified Scope and Boundaries\u003C\u002Fh2>\n\u003Cp>The verified number for this record should be maintained as 2,481,121. This value represents unique email coverage; it should not be assumed that each record corresponds to a single real person. Even if the dataset has been included within a larger sales archive, this is not sufficient to add the numbers or data fields of different companies to the Ge.tt record. Coverage should be limited to verified Ge.tt data only.\u003C\u002Fp>\n\u003Cp>Verified data fields are email addresses, names, passwords, and social media profiles. The password field should be specified as a SHA-256 hash. Phone number, physical address, payment card, official ID, date of birth, IP address, file content, private file link, download history, or plaintext password should not be added to the record as they are not verified fields. This restriction shows the correct risk level to the user and prevents the addition of unverified fields based on the file-sharing context.\u003C\u002Fp>\n\u003Ch2>User Groups at Risk\u003C\u002Fh2>\n\u003Cp>The highest risk is for users who reuse the password they use for their Ge.tt account on other accounts. File sharing services are often used together with email and social media accounts. If the same email or password is valid for other cloud storage, email, social media, or work accounts, attackers can use this connection in account takeover attempts.\u003C\u002Fp>\n\u003Cp>People who use their file-sharing account under the same identity as their social media profiles should also be careful. When name, email, and social profile ID are found together, messages themed around fake file sharing, contracts, invoices, portfolios, or media links can be prepared. Users who receive work files, project sharing, or media download messages in particular should not open files without verifying the authenticity of the links.\u003C\u002Fp>\n\u003Ch2>Urgent Measures to Be Taken\u003C\u002Fh2>\n\u003Cp>The user with an email address in this record should ensure that their old password used on the Ge.tt account is not left on any other account. If the same or similar password was used on other services, it should immediately be changed to a long, unique, and hard-to-guess password. Using a password manager reduces the risk of reuse. Using SHA-256 hash does not make password reuse safe.\u003C\u002Fp>\n\u003Cp>Multi-factor authentication should be enabled for email accounts, cloud storage, social media, and work accounts. When messages themed around file sharing, download notifications, security alerts, or account verification are received, logging in through a link should be avoided; the official site address should be entered manually. Before opening unexpected attachments and file links, the sender and domain name should be checked. Public email and contact information on social media accounts should also be reviewed.\u003C\u002Fp>\n\u003Ch2>Long-Term Security Strategies\u003C\u002Fh2>\n\u003Cp>The Ge.tt incident shows that when credentials used in file-sharing accounts are linked to social media and email accounts, it creates a broader risk. Users should not reuse the same password across cloud, file-sharing, email, and social media accounts. Old file-sharing accounts should be closed or isolated with unique passwords. Using the same social profile links across many services increases the risk of profile matching.\u003C\u002Fp>\n\u003Cp>The main lesson for service providers is that the process of storing passwords should not be left solely to general hash functions, and social profile identifiers should not be kept for an unnecessary period. Modern, cost-adjusted methods should be preferred for password storage; in cases where incidents involve data sharing and sales archives, users should be clearly informed which fields are affected. If file contents are not affected, this boundary should also be explained clearly.\u003C\u002Fp>\n\u003Ch2>Record Control and User Action\u003C\u002Fh2>\n\u003Cp>During record verification for Ge.tt violation, the result indicates whether the entered email address is present in this verified dataset. If the result is positive, the email address, name, social media profile ID, and SHA-256 password hash should be considered within the scope of risk. If the result is negative, it means that no match was found in this particular dataset; this does not prove that the person is not involved in other file sharing or social platform violations.\u003C\u002Fp>\n\u003Cp>The correct user actions are to completely abandon the old password, change all reused passwords, use multi-factor protection on email and cloud accounts, review social profile connections, and be cautious against fake messages themed around file sharing. This record does not mean that file contents have leaked; however, due to credentials and social profile context, it poses a targeted phishing risk.\u003C\u002Fp>","","Ge.tt Data Breach (2.5 Million Reported Records)","Ge.tt Data Breach. 2.5 Million reported records were reported. Reported data: Email addresses, Names, Passwords. Review the scope, risks, and protective steps.","\u002Fuploads\u002Flogo\u002Fge_tt.webp",false,{"name":34,"sector":35,"country":36,"website":9,"websiteArchiveUrl":37,"websiteStatus":38,"websiteCheckedAt":39},"Ge.tt","File Sharing","Denmark","https:\u002F\u002Fweb.archive.org\u002Fweb\u002F20210307034116\u002Fhttp:\u002F\u002Fge.tt\u002F","archived","2026-07-29T11:30:22.391Z"]