[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fgh5207f4thzz":3},{"success":4,"breach":5},true,{"_id":6,"name":7,"title":8,"slug":7,"domain":9,"breachDate":10,"addedDate":11,"modifiedDate":12,"contentUpdatedAt":12,"source":13,"sourceUrl":14,"sourceUrls":15,"pwnCount":16,"affectedCount":16,"affectedCountStatus":17,"affectedCountLowerBound":18,"affectedCountUnit":19,"hasEnglishDescription":4,"severity":20,"dataClasses":21,"description":26,"seoTitle":27,"seoTitleEn":28,"seoDescription":27,"seoDescriptionEn":29,"logoUrl":30,"isVerified":4,"isSensitive":4,"isSpamList":31,"isMalware":31,"company":32},"68e3266eda11adda48825258","kaneva","Kaneva 2016 Data Breach","kaneva.com","2016-07-01T00:00:00.000Z","2023-12-09T07:00:29.000Z","2026-07-29T20:14:44.747Z","Verified breach record","https:\u002F\u002Fweb.archive.org\u002Fweb\u002F20160630120847id_\u002Fhttp:\u002F\u002Fwww.kaneva.com\u002F",[14],3901179,"known",null,"email_identifiers","Critical",[22,23,24,25],"Dates of birth","Email addresses","Passwords","Usernames","\u003Cp>\u003Cstrong>The Kaneva 2016 data breach\u003C\u002Fstrong> concerns account data attributed to the social-networking and free 3D virtual-world service. A verified external breach record reports a July 1, 2016 date, 3,901,179 unique email addresses, and four structured data classes. The production email-only job processed 3,908,470 valid lines and created 3,908,307 unique email associations in the live index. These measures belong to different corpus layers and are not added together.\u003C\u002Fp>\n\n\u003Ch2>What was verified about the event and service?\u003C\u002Fh2>\n\u003Cp>The current verified external narrative says 3.9 million user records from the now-defunct Kaneva service were exposed and contained email addresses, usernames, dates of birth, and salted MD5 password hashes. Its structured scope lists the same four classes. No public operator notice, regulator record, initial-access method, actor, access duration, or publication date was found. July 1 is the external record's event date and is not interpreted as the exact moment of network access.\u003C\u002Fp>\n\n\u003Cp>A June 30, 2016 archive presents Kaneva as a service combining social networking with a free 3D virtual world where users could build and explore virtual worlds with friends. The archive supports organization and service identity; it is not an independent incident notice. Because kaneva.com now redirects to an unrelated website, the public record links to the incident-period archive instead.\u003C\u002Fp>\n\n\u003Ch2>Which data types are in scope?\u003C\u002Fh2>\n\u003Cp>The verified external classes are dates of birth, email addresses, passwords, and usernames. Passwords are described as salted MD5 hashes; plaintext-password exposure has not been established. A salt makes precomputed lookup tables less useful, but MD5 is a fast and weak method for modern password storage.\u003C\u002Fp>\n\n\u003Cp>Names, phone numbers, physical addresses, government IDs, payment cards, private messages, avatar content, and virtual-world activity are not verified classes. An email match alone does not prove that a person held a Kaneva account, shared a row with a particular birth date, username, or hash, or used the virtual world.\u003C\u002Fp>\n\n\u003Ch2>Why do the external and local counts differ?\u003C\u002Fh2>\n\u003Cp>The 3,901,179 value is the unique-email measure in the external corpus. The local index contains 3,908,307 unique email associations, 7,128 above the external measure, while the 3,908,470 valid processed lines are 163 above the local unique associations. Because corpus version, normalization, and deduplication details have not been reconciled, no cause is assigned to the differences.\u003C\u002Fp>\n\n\u003Cp>The local job contains email addresses only. Dates of birth, usernames, and password hashes are externally verified classes, not locally stored fields from this production import. People who independently know that they reused an old Kaneva password on another service can replace that copy with a unique password and enable multifactor authentication where available.\u003C\u002Fp>","","Kaneva 2016 Data Breach (3.9 Million Email Identifiers)","The 2016 Kaneva breach contains 3,901,179 verified unique emails. Review four external fields and 3,908,307 local email associations.","\u002Fuploads\u002Flogo\u002Fkaneva_com.webp",false,{"name":33,"sector":34,"country":35,"website":9,"websiteArchiveUrl":14,"websiteStatus":36,"websiteCheckedAt":37},"Kaneva","Social Media","United States","archived","2026-07-29T20:03:00.000Z"]