All Breaches
October 3, 2020 Verified Sensitive Record Avatar service

Gravatar Data Breach

The 2020 Gravatar mass-scraping incident was serial enumeration of a public profile API, not a password or private-database intrusion.

114 Million
Email Identifiers
4
Data Types
Critical
Severity
Yes
Verification

Exposed Data Types

4
Email addresses
Public profile names
Public profile usernames
Md5 email-reference hashes

Additional Information

Added DateDecember 5, 2021
Breach DateOctober 3, 2020
Domaingravatar.com
Last Content UpdateJuly 29, 2026

Verification and editorial method

LeakData compares the incident name, date, affected-record count, and exposed data types with accessible sources. Unverified fields are not presented as facts, and records are updated when new evidence becomes available.

Report missing or incorrect information