[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f37unz7laaz2pb":3},{"success":4,"breach":5},true,{"_id":6,"name":7,"title":8,"slug":9,"domain":10,"breachDate":11,"addedDate":12,"modifiedDate":13,"contentUpdatedAt":13,"source":14,"sourceUrl":15,"sourceUrls":16,"pwnCount":18,"affectedCount":18,"affectedCountStatus":19,"affectedCountLowerBound":20,"affectedCountUnit":21,"hasEnglishDescription":4,"severity":22,"dataClasses":23,"description":28,"seoTitle":29,"seoTitleEn":30,"seoDescription":29,"seoDescriptionEn":31,"logoUrl":32,"isVerified":4,"isSensitive":4,"isSpamList":33,"isMalware":33,"company":34},"68e3266eda11adda48825208","Gravatar","Gravatar Data Breach","gravatar","gravatar.com","2020-10-03T00:00:00.000Z","2021-12-05T22:45:58.000Z","2026-07-29T11:13:00.741Z","Third party breach","https:\u002F\u002Fwww.bleepingcomputer.com\u002Fnews\u002Fsecurity\u002Fonline-avatar-service-gravatar-allows-mass-collection-of-user-info\u002F",[15,17],"https:\u002F\u002Fwptavern.com\u002Fgravatar-says-it-was-not-hacked-after-have-i-been-pwned-service-notifies-users-of-a-breach",113990759,"known",null,"email_identifiers","Critical",[24,25,26,27],"Email addresses","Public profile names","Public profile usernames","MD5 email-reference hashes","\u003Cp>\u003Cstrong>The 2020 Gravatar mass-scraping incident\u003C\u002Fstrong> was serial enumeration of a public profile API, not a password or private-database intrusion. Researcher Carlo Di Dato disclosed on October 3, 2020 that a numeric-ID JSON route allowed sequential profile collection with virtually no rate limiting. Gravatar said it “was not hacked,” that usernames and MD5 hashes used as email references were scraped, and that it blocked bulk harvesting.\u003C\u002Fp>\u003Cp>Names and usernames were public profile fields; the email address was represented by an MD5 hash. The hash was not encrypted and decrypted. Because unsalted MD5 is deterministic, candidate or known emails could be hashed and matched to recover original email strings.\u003C\u002Fp>\u003Cp>public breach source reports approximately 167 million scraped profiles and 113,990,759 recovered unique emails distributed with names and usernames. The 113,990,759 figure is not people, active users, or newly exposed addresses; 72% of recovered emails were already present in public breach source's corpus from previous incidents. October 3 is the technique-disclosure date, not a proven start day for collection of the final corpus.\u003C\u002Fp>\u003Cp>There is no local person-level corpus. The record does not establish current Gravatar use, profile ownership, name and username co-occurrence, password compromise, or misuse. Email-to-name, pseudonym, and cross-site links can de-anonymize participation in sensitive communities and must remain private; users should review only the Gravatar fields that are still publicly visible.\u003C\u002Fp>","","Gravatar Data Breach (114 Million Email Identifiers)","Gravatar Data Breach. 114 Million email identifiers were reported. Reported data: Email addresses, Public profile names, Public profile usernames. Review the…","\u002Fuploads\u002Flogo\u002Fgravatar_com.webp",false,{"name":7,"sector":35,"country":36,"website":10,"websiteArchiveUrl":29,"websiteStatus":29,"websiteCheckedAt":20},"Avatar service","United States"]