[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f1dctrrsz8znn0":3},{"success":4,"breach":5},true,{"_id":6,"name":7,"title":8,"slug":7,"domain":9,"breachDate":10,"addedDate":11,"modifiedDate":12,"contentUpdatedAt":13,"source":14,"sourceUrl":15,"sourceUrls":16,"pwnCount":19,"affectedCount":19,"affectedCountStatus":20,"affectedCountLowerBound":21,"affectedCountUnit":22,"hasEnglishDescription":4,"severity":23,"dataClasses":24,"description":38,"seoTitle":39,"seoTitleEn":40,"seoDescription":39,"seoDescriptionEn":41,"logoUrl":42,"isVerified":4,"isSensitive":43,"isSpamList":43,"isMalware":43,"company":44},"68e3266eda11adda48825275","liker","Liker Data Breach","liker.com","2021-03-08T00:00:00.000Z","2021-03-13T04:15:16.000Z","2021-03-24T01:57:46.000Z","2026-07-18T23:53:17.825Z","Website hack","https:\u002F\u002Fdatabreach.com\u002Fbreach\u002Fliker.com-2021",[15,17,18],"https:\u002F\u002Foutsmartbigbrother.medium.com\u002Fsocial-media-site-liker-goes-offline-claims-we-were-attacked-by-trumpers-34aff5d48366","https:\u002F\u002Fliker.com\u002F",465141,"known",null,"unknown","High",[25,26,27,28,29,30,31,32,33,34,35,36,37],"Auth tokens","Dates of birth","Education levels","Email addresses","Geographic locations","IP addresses","Names","Passwords","Phone numbers","Private messages","Security questions and answers","Social media profiles","Usernames","\u003Cp>The Liker data breach is a confirmed security incident affecting the social networking service called Liker on March 8, 2021. Records show that a large number of personal and in-account data fields were exposed along with the email addresses of 465,141 unique accounts. Liker was a community-focused platform that marketed itself as a kinder and smarter social network; the prolonged offline period of the service after the breach indicates that the incident posed a broader account and privacy risk not limited to password changes. The exposed fields include session tokens, birthdates, education information, email addresses, geographic locations, IP addresses, names, phone numbers, private messages, security questions and answers, social media profile links, usernames, and bcrypt-protected passwords.\u003C\u002Fp>\n\u003Ch2>Leaking Data Types and Risks\u003C\u002Fh2>\n\u003Cp>The risk of this record arises from the diversity of data types. When an email address, username, and name information are found together, it becomes easier to match a person across different social networks, forums, or work accounts. A phone number and IP address can make phishing messages more convincing. Profile fields such as date of birth, education level, and geographic location provide additional context in social engineering scenarios. The exposure of private messages increases the privacy risk; users' personal relationships, political views, circle of friends, account names on other platforms, or communication preferences can be misused by third parties.Having security questions and answers in plain text is a more critical issue; if the same question answers are used in other services, attackers may target password reset processes. Protecting passwords with bcrypt is a positive technical detail, but the risk still persists for weak or reused passwords.\u003C\u002Fp>\n\u003Ch2>Verified Scope and Boundaries\u003C\u002Fh2>\n\u003Cp>The verified scope concerns Liker social network accounts. This record does not mean that Gab, Parler, Facebook, Twitter, or any other social network account was directly compromised; the incident is limited to the exposure of user data held by the Liker service. The number 465,141 refers to unique email or account matches. Although lower row counts may appear in some search sources, this discrepancy may be due to the measurement distinction between the accessible subset of data and the number of unique accounts. The verified data fields are extensive, but payment card numbers, bank accounts, official ID numbers, or passport data are not among the verified fields in this record. Password information has been verified to be stored with bcrypt; plaintext password representation is not accurate for this record.On the other hand, having the security question and answers in plain text poses an additional account recovery risk if users use the same answers for other accounts.\u003C\u002Fp>\n\u003Ch2>User Groups at Risk\u003C\u002Fh2>\n\u003Cp>The highest risk arises for people who use the same email address, username, or phone number on their Liker account as they do on other social networks. If the same password is repeated across different services, the risk of account takeover is not completely eliminated, even though bcrypt protection increases the cost of an attack. Users who fill in security question answers with real and recurring information should also be careful; answers such as mother's maiden name, place of birth, elementary school, or pet name can become strong clues for an attacker if they are the same on other accounts. The privacy risk is greater for people who have shared personal connections, other account names, political discussions, address hints, or phone information via private messages on Liker.Social media profile links also make it easier to track a person across platforms. Since the service is offline, it may not be possible to directly secure the Liker account; therefore, the risk is transferred to other accounts used with the same credentials.\u003C\u002Fp>\n\u003Ch2>Urgent Measures to Be Taken\u003C\u002Fh2>\n\u003Cp>If the password used on the Liker account has been used anywhere else, it should be changed immediately. Priority should be given to email accounts, social media accounts, messaging services, and accounts of financial importance. A unique and long password should be chosen for each account, and two-factor authentication should be enabled wherever possible. If the security question answers used on Liker are valid on other services as well, these answers should be renewed with random, unpredictable, and service-specific values. Suspicious links sent to the same phone number or email address, fake support notifications, and messages claiming old social network accounts should be carefully examined. If information belonging to other people appears in private messages, it is appropriate to provide the relevant people with brief and clear information.Account recovery emails, unknown device sessions, and unexpected password reset requests should be monitored as security signals.\u003C\u002Fp>\n\u003Ch2>Long-Term Security Strategies\u003C\u002Fh2>\n\u003Cp>This event shows that profile fields stored on social media accounts can continue to generate risks even years later. In the long term, a separate password should be maintained for each social network, forum, and community account; repeated passwords should be cleaned with the help of a password manager. In services that use the security question system, random answers specific to each service should be preferred instead of real answers. Fields such as date of birth, education level, phone number, and location should not be shared if they are not mandatory in the profile. It should be remembered that social media profile links connect old and new accounts; while using the same username everywhere is practical, it makes it easier for attackers to create a profile of a person.Private messages should be considered as permanent data, and login information for other accounts, phone numbers, addresses, identity hints, or sensitive relationship information should not be kept within the message. Even if the old service is closed, data leaked from that service can be reused in new phishing attempts.\u003C\u002Fp>\n\u003Ch2>Record Control and User Action\u003C\u002Fh2>\n\u003Cp>This record should be checked by individuals who have previously opened a Liker account, received a Liker invitation, or used the same email address in social network trials. If a match is found, the first action is to separate all accounts opened with the same email and password pair. Then, it should be reviewed whether the phone number, username, and security question answers are repeated on other services. Since the Liker service is offline, it may not be possible to directly change account settings; therefore, protection steps should be applied to the associated email account and other social platforms. Even if no match is found, this incident demonstrates the long-term risk of leaving unnecessary personal data on social networks. The healthiest approach is to reduce old accounts, use unique passwords, randomize security question answers, and avoid sharing information that could be used for authentication in private messages.\u003C\u002Fp>","","Liker Data Breach (465.1 Thousand Reported Records)","Liker Data Breach. 465.1 Thousand reported records were reported. Reported data: Auth tokens, Dates of birth, Education levels. Review the scope, risks, and…","\u002Fuploads\u002Flogo\u002Fliker_com.webp",false,{"name":45,"sector":46,"country":47,"website":9,"websiteArchiveUrl":39,"websiteStatus":39,"websiteCheckedAt":21},"Liker","Social Media","United States"]