[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f25hf3d7qpil57":3},{"success":4,"breach":5},true,{"_id":6,"name":7,"title":8,"slug":9,"domain":10,"breachDate":11,"addedDate":12,"modifiedDate":13,"contentUpdatedAt":13,"source":14,"sourceUrl":15,"sourceUrls":16,"pwnCount":18,"affectedCount":18,"affectedCountStatus":19,"affectedCountLowerBound":20,"affectedCountUnit":21,"hasEnglishDescription":4,"severity":22,"dataClasses":23,"description":28,"seoTitle":29,"seoTitleEn":30,"seoDescription":29,"seoDescriptionEn":31,"logoUrl":32,"isVerified":4,"isSensitive":33,"isSpamList":33,"isMalware":33,"company":34},"68e3266eda11adda48825238","iMesh","iMesh Data Breach","imesh","imesh.com","2013-09-22T00:00:00.000Z","2016-07-02T05:42:13.000Z","2026-07-29T14:12:58.498Z","Verified breach record, independent security reporting, and archived company website","https:\u002F\u002Fwww.bitdefender.com\u002Fen-us\u002Fblog\u002Fhotforsecurity\u002F51-million-imesh-accounts-for-purchase-on-the-dark-web",[15,17],"https:\u002F\u002Fweb.archive.org\u002Fweb\u002F20161229041843\u002Fhttp:\u002F\u002Fimesh.com\u002F",49467477,"known",null,"accounts","Critical",[24,25,26,27],"Email addresses","IP addresses","Passwords","Usernames","\u003Cp>\u003Cstrong>The iMesh 2013 data breach\u003C\u002Fstrong> involved exposed account data from the now-defunct media and file-sharing service. A verified breach record places the event in September 2013 and reports 49,467,477 affected accounts. Independent reporting in 2016 estimated more than 51 million accounts in the dataset offered for sale; because the sources do not explain the methodology or scope difference, the figures are not combined and the verified index's more conservative count is used.\u003C\u002Fp>\n\n\u003Cp>The data was reported for sale on a dark-web market in mid-2016. A company representative said at the time that he was not aware of a breach; the event was later added to a verified breach record. Public sources do not publish the exact initial access method or a confirmed actor identity, so those details are left unresolved.\u003C\u002Fp>\n\n\u003Ch2>What information was present?\u003C\u002Fh2>\n\u003Cp>Confirmed fields are email addresses, IP addresses, usernames, and password hashes in salted MD5 form. A hash is not a plaintext password, but MD5 is weak by current password-storage standards and short or common passwords may be guessed. The sources do not list payment cards, phone numbers, physical addresses, government identification, or health information for this event.\u003C\u002Fp>\n\n\u003Ch2>Safe next steps and archive link\u003C\u002Fh2>\n\u003Cp>If the iMesh password used in 2013, or a similar one, was reused on another active account, create a unique password there and enable multifactor authentication. Accounts using the same email address can be reviewed for unfamiliar sessions, recovery addresses, and forwarding rules. Password-reset, copyright, or account-closure messages claiming to represent the former iMesh service should not be assumed trustworthy. Because imesh.com no longer resolves in DNS, the company link points to a verified Wayback Machine archive.\u003C\u002Fp>","","iMesh 2013 Data Breach (49.5 Million Accounts Affected)","The iMesh breach affected 49,467,477 accounts. Review the email, IP, username, and salted-MD5 password-hash scope.","\u002Fuploads\u002Flogo\u002Fimesh_com.webp",false,{"name":7,"sector":35,"country":36,"website":10,"websiteArchiveUrl":17,"websiteStatus":37,"websiteCheckedAt":38},"Media and file sharing software","United States","archived","2026-07-29T11:30:22.391Z"]