[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f1gqn5xxmjmf3t":3},{"success":4,"breach":5},true,{"_id":6,"name":7,"title":8,"slug":7,"domain":9,"breachDate":10,"addedDate":11,"modifiedDate":12,"contentUpdatedAt":12,"source":13,"sourceUrl":14,"sourceUrls":15,"pwnCount":17,"affectedCount":17,"affectedCountStatus":18,"affectedCountLowerBound":19,"affectedCountUnit":20,"hasEnglishDescription":4,"severity":21,"dataClasses":22,"description":28,"seoTitle":29,"seoTitleEn":30,"seoDescription":29,"seoDescriptionEn":31,"logoUrl":32,"isVerified":4,"isSensitive":33,"isSpamList":33,"isMalware":33,"company":34},"68e3266eda11adda4882525e","knuddels","Knuddels 2018 Data Breach","knuddels.de","2018-09-05T00:00:00.000Z","2019-04-08T21:11:56.000Z","2026-07-29T22:11:32.427Z","company notice and verified breach index","https:\u002F\u002Fforum.knuddels.de\u002Fubbthreads.php?ubb=showflat&Number=2916081",[14,16],"https:\u002F\u002Fwww.welivesecurity.com\u002F2018\u002F11\u002F27\u002Fgerman-chat-site-faces-fine-gdpr\u002F",808330,"known",null,"email_identifiers","High",[23,24,25,26,27],"Email addresses","Geographic locations","Names","Passwords","Usernames","\u003Cp>\u003Cstrong>The Knuddels 2018 data breach\u003C\u002Fstrong> covers the user-data incident disclosed by the German chat platform in its official forum. The verified external corpus contains 808,330 unique email addresses and five classes: email addresses, geographic locations, names, passwords, and usernames. The company's statements concerning approximately 808,000 emails, 1,872,000 nickname-password pairs, and 330,000 verified email owners are different measures; they are neither added nor presented as a single count of people or accounts.\u003C\u002Fp>\n\n\u003Ch2>What does the official timeline establish?\u003C\u002Fh2>\n\u003Cp>According to Knuddels' forum disclosure, an unknown person published 8,000 member records on Pastebin on September 5, 2018. The company authenticated the data on September 6, temporarily disabled affected credentials, and prepared password-reset measures. On September 7 it received a link to a larger file containing 1,872,000 nicknames and passwords; Knuddels said it then required all members to replace their passwords and sent notifications.\u003C\u002Fp>\n\n\u003Cp>The first 8,000 records reportedly contained nicknames and passwords, plus email in 57% of cases, a first name in 41%, and a place of residence in 30%. The company also said about 330,000 of approximately 808,000 email addresses were verified and represented distinct people. The external corpus measure of 808,330 unique emails counts email identifiers; it is not substituted for the company's verified-person subset.\u003C\u002Fp>\n\n\u003Ch2>What is known about plaintext passwords and the cause?\u003C\u002Fh2>\n\u003Cp>Knuddels explained that although it introduced password hashes in 2012, it retained an unencrypted version for an older filter designed to stop users from sharing passwords in chats. The company removed those versions and disabled the filter on September 7, 2018. Its investigation identified a backup server with an outdated operating system as a first possible weakness and shut it down; because the forum post did not present that finding as a final initial-access conclusion, it is not stated here as the definitive cause.\u003C\u002Fp>\n\n\u003Cp>The Baden-Württemberg data-protection authority later fined Knuddels €20,000 for storing passwords in plaintext. The regulator also took account of the company's prompt notification, cooperation, transparency, and security improvements. The fine is not a measure of people or email addresses in the corpus.\u003C\u002Fp>\n\n\u003Ch2>How does the local index differ from the external corpus?\u003C\u002Fh2>\n\u003Cp>The completed production job processed 808,156 valid lines from an email-only file formed by taking the union of two explicit email columns and created the same number of unique email associations. Usernames, passwords, names, locations, and other text fields were excluded from the local import. The local email count is 174 below the external measure; because the source version and normalization details are not identical, the difference is not assigned a cause.\u003C\u002Fp>\n\n\u003Cp>Knuddels' official site and incident forum remain operational. A local email match does not prove membership, real-world identity, city, or continued password use. If a password used in 2018 was reused in the same or a similar form on another service, it should be replaced there with a unique password. Unexpected sign-in or password-reset messages should be checked by opening the official service directly rather than following the message link.\u003C\u002Fp>","","Knuddels 2018 Data Breach (808.3 Thousand Email Identifiers)","The Knuddels 2018 breach contains 808,330 verified unique emails and plaintext passwords; the local index contains only 808,156 email associations.","\u002Fuploads\u002Flogo\u002Fknuddels_de.webp",false,{"name":35,"sector":36,"country":37,"website":9,"websiteArchiveUrl":29,"websiteStatus":38,"websiteCheckedAt":39},"Knuddels","Social Media","Germany","active","2026-07-29T22:06:00.000Z"]