[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f3s2rgsaybd9jr":3},{"success":4,"breach":5},true,{"_id":6,"name":7,"title":8,"slug":7,"domain":9,"breachDate":10,"addedDate":11,"modifiedDate":12,"contentUpdatedAt":13,"source":14,"sourceUrl":15,"sourceUrls":16,"pwnCount":22,"affectedCount":22,"affectedCountStatus":23,"affectedCountLowerBound":24,"affectedCountUnit":25,"hasEnglishDescription":4,"severity":26,"dataClasses":27,"description":35,"seoTitle":36,"seoTitleEn":37,"seoDescription":36,"seoDescriptionEn":38,"logoUrl":39,"isVerified":4,"isSensitive":40,"isSpamList":40,"isMalware":40,"company":41},"68e3266eda11adda4882527e","liveauctioneers","LiveAuctioneers Data Breach","liveauctioneers.com","2020-06-19T00:00:00.000Z","2020-08-22T04:38:40.000Z","2020-08-22T04:54:52.000Z","2026-07-18T23:53:36.053Z","Third party breach","https:\u002F\u002Foag.ca.gov\u002Fsystem\u002Ffiles\u002Fdataincident.pdf",[15,17,18,19,20,21],"https:\u002F\u002Fportswigger.net\u002Fdaily-swig\u002Fliveauctioneers-data-breach-millions-of-cracked-passwords-for-sale-say-researchers","https:\u002F\u002Fwww.bleepingcomputer.com\u002Fnews\u002Fsecurity\u002Fliveauctioneers-reports-data-breach-after-user-records-sold-online\u002F","https:\u002F\u002Fwww.securityweek.com\u002Fliveauctioneers-data-breach-impacts-34-million-users\u002F","https:\u002F\u002Fwww.cloudsek.com\u002Fthreatintelligence\u002F3-4-m-liveauctioneers-users-pii-and-cracked-passwords-for-sale-on-data-sharing-forum","https:\u002F\u002Fwww.liveauctioneers.com\u002F",3385862,"known",null,"unknown","Critical",[28,29,30,31,32,33,34],"Email addresses","IP addresses","Names","Passwords","Phone numbers","Physical addresses","Usernames","\u003Cp>The LiveAuctioneers data breach is an account data incident on June 19, 2020, affecting users of liveauctioneers.com, a live auction service for art, antiques, jewelry, and collectible items. The record covers approximately 3,385,862 accounts and involves unauthorized access through a data processing\u002FIT provider working with LiveAuctioneers systems. The company became aware of the incident on July 11, 2020, notified users, and disabled old passwords.\u003C\u002Fp>\u003Cp>The verified data fields are email addresses, IP addresses, first and last name information, password records, phone numbers, physical addresses, and usernames. The password field is particularly important because it has been reported that passwords in the dataset are stored as unsalted MD5 hash values and that some password matches were later cracked. This record does not imply that full payment card numbers or auction histories have been leaked. User risk should primarily be assessed through account identity, contact information, address information, and password reuse.\u003C\u002Fp>\u003Ch2>Leaked Data Types and Risks\u003C\u002Fh2>\u003Cp>The data fields in this breach can broadly define the identity and contact profile of an auction account. Email address and username are primary contact points for account access attempts and phishing messages. Full name, phone number, and physical address can make fraud attempts sent under the pretense of fake shipping notifications, fake invoices, fake payment reminders, account security alerts, or high-value collectible products more convincing. IP addresses also add risk in the context of account behavior and approximate location.\u003C\u002Fp>\u003Cp>The fact that password records are protected with unsalted MD5 hash values increases the risk level. MD5 is considered weak for modern password storage; especially short, predictable, or passwords seen in other leaks can be cracked quickly. If the same password is reused across email, payment, social media, marketplace, or other auction accounts, a single data incident can spread to multiple accounts. Fields such as physical address and phone number can also be used in offline fraud, fake delivery calls, and personalized threat scenarios.\u003C\u002Fp>\u003Ch2>Verified Scope and Boundaries\u003C\u002Fh2>\u003Cp>The verified scope of this record is based on the June 19, 2020 incident and approximately 3,385,862 accounts. The LiveAuctioneers notice states that an unauthorized third party accessed certain user account data through a data processing partner. The main data classes that should be kept in the record are email addresses, IP addresses, names, passwords, phone numbers, physical addresses, and usernames. Not all of these fields may be present in each user account; therefore, the description should not assume that all users were affected by every data field.\u003C\u002Fp>\u003Cp>The important boundary related to the incident lies with payment and auction history. The company's notification stated that there is no evidence that full payment card numbers were accessed and it is not believed that the auction history was affected. Therefore, the record should be retained without adding a data class for card numbers or auction history. The source of the incident should be considered as a security vulnerability on the supplier side, not directly the auction workflow of the service. This distinction shows the correct risk area without generating unnecessary alarm for the user.\u003C\u002Fp>\u003Ch2>User Groups at Risk\u003C\u002Fh2>\u003Cp>The highest risk applies to people who reuse the password they use for their LiveAuctioneers account on other services. Especially if the same email and password combination is also used for email accounts, non-bank payment services, social media, other marketplaces, shipping accounts, or auction sites, automated account attempts can be expected. Users who purchase collectible items, antiques, jewelry, or artwork may also become more attractive targets for targeted fraud, because their name, phone number, address, and platform interest can be used together.\u003C\u002Fp>\u003Cp>Users whose physical address and phone number are included in the records should be careful not only of online threats but also of fake requests received via phone and mail. Attackers may pose as if they have a legitimate auction account and contact users under the pretext of payment confirmation, shipping fees, customs charges, or account verification. Additional information such as IP address and username can aid in personalizing the attack. People who no longer use their old accounts are also at risk, as old passwords may remain on other accounts for years.\u003C\u002Fp>\u003Ch2>Urgent Measures to Be Taken\u003C\u002Fh2>\u003Cp>If your email address is found in this record, first compare the old password used on the LiveAuctioneers account with other accounts. If the same or similar password exists elsewhere, set a long and unique new password for each account. Priority should be given to email accounts, payment services, marketplaces, social media, and shipping accounts. Using a password manager makes it easier to find repeated passwords and generate strong values for each account.\u003C\u002Fp>\u003Cp>The session history, registered addresses, phone numbers, and account recovery information should be reviewed on the LiveAuctioneers account. Two-factor authentication should be enabled on supported accounts, unknown device sessions should be closed, and suspicious email or SMS links should not be clicked. Messages related to auctions, delivery, payment, shipping, account security, or special offers should be carefully examined. Even if the full card number is not among the verified data classes of this record, users should monitor their payment statements and account transactions for unusual activity.\u003C\u002Fp>\u003Ch2>Long-Term Security Strategies\u003C\u002Fh2>\u003Cp>This incident demonstrates that auction and marketplace accounts are valuable not only in terms of purchase history but also in terms of identity and contact information. In the long run, unique passwords for each service, two-factor authentication, regular session checks, and closing unnecessary accounts are the basic lines of defense. Users should minimize the addresses and phone numbers registered in old auction accounts, close accounts that are no longer used, and avoid using the same username across different services in a way that creates unnecessary links.\u003C\u002Fp>\u003Cp>On the service provider side, limiting supplier access, strong password hashing algorithms, event monitoring, regular security audits, and prompt user notification are critical. On the user side, the risk does not end with changing the password of a single account; when the email address, phone number, physical address, and username are considered together, the social engineering threat can persist for a long time. Therefore, users should regularly review account security and take into account that old data leaks could be reused in new fraud messages.\u003C\u002Fp>\u003Ch2>Record Control and User Action\u003C\u002Fh2>\u003Cp>If a result appears positive on LeakData for LiveAuctioneers, this record is related to the account data incident from the data processing partner dated June 19, 2020. The first action is to identify the affected email address and the old password used on the LiveAuctioneers account. Then, all accounts where the same password may have been used should be listed, each should be updated with a unique new password, and two-factor authentication should be enabled wherever possible. Completely different values should be preferred instead of minor password changes.\u003C\u002Fp>\u003Cp>In the next check, focus should be on targeted fraud attempts that may come with phone number, address, and full name information. Messages such as fake support messages, fake auction results, payment completion requests, delivery fees, or account security notifications should be checked by going directly to the official site. For this record, the verified data classes are email addresses, IP addresses, names, passwords, phone numbers, physical addresses, and usernames; payment card numbers or auction history should not be added to this record.\u003C\u002Fp>","","LiveAuctioneers Data Breach (3.4 Million Reported Records)","LiveAuctioneers Data Breach. 3.4 Million reported records were reported. Reported data: Email addresses, IP addresses, Names. Review the scope, risks, and…","\u002Fuploads\u002Flogo\u002Fliveauctioneers_com.webp",false,{"name":42,"sector":43,"country":44,"website":9,"websiteArchiveUrl":36,"websiteStatus":36,"websiteCheckedAt":24},"LiveAuctioneers","Retail","United States"]