[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f2tmryjsz41vje":3},{"success":4,"breach":5},true,{"_id":6,"name":7,"title":8,"slug":9,"domain":10,"breachDate":11,"addedDate":12,"modifiedDate":13,"contentUpdatedAt":14,"source":15,"sourceUrl":16,"sourceUrls":17,"pwnCount":22,"affectedCount":22,"affectedCountStatus":23,"affectedCountLowerBound":24,"affectedCountUnit":25,"hasEnglishDescription":4,"severity":26,"dataClasses":27,"description":31,"seoTitle":32,"seoTitleEn":33,"seoDescription":32,"seoDescriptionEn":34,"logoUrl":35,"isVerified":4,"isSensitive":36,"isSpamList":36,"isMalware":36,"company":37},"68e3266eda11adda48825281","LiveJournal","LiveJournal Data Breach","livejournal","livejournal.com","2017-01-01T00:00:00.000Z","2020-05-26T22:05:10.000Z","2020-05-26T23:08:58.000Z","2026-07-19T14:59:31.403Z","Alleged credential exposure","https:\u002F\u002Fnews.livejournal.com\u002F155859.html",[16,18,19,20,21],"https:\u002F\u002Fdw-news.dreamwidth.org\u002F40167.html","https:\u002F\u002Fdw-news.dreamwidth.org\u002F38612.html","https:\u002F\u002Fwww.helpnetsecurity.com\u002F2020\u002F05\u002F27\u002Flivejournal-data-dump\u002F","https:\u002F\u002Fwww.bitdefender.com\u002Fen-us\u002Fblog\u002Fhotforsecurity\u002F26-million-livejournal-users-warned-that-their-passwords-have-been-breached",26372781,"known",null,"unknown","Critical",[28,29,30],"Email addresses","Passwords","Usernames","\u003Cp>An account file associated with LiveJournal was widely redistributed in May 2020 and contained 26,372,781 unique accounts. It included email addresses and usernames that matched accounts on the platform alongside plaintext passwords. LiveJournal disputed direct attribution of a breach, saying the data might have been compiled from multiple sources and largely falsified.\u003C\u002Fp>\u003Ch2>Types of Exposed Data and Risks\u003C\u002Fh2>\u003Cp>The supported data classes for this record are email addresses, passwords, and usernames. Plaintext passwords expose people who reused them on other services to credential-stuffing attacks. Blog posts, private messages, payment information, phone numbers, IP addresses, and physical addresses are not verified data classes for this record.\u003C\u002Fp>\u003Ch2>Breach Timeline and Technical Details\u003C\u002Fh2>\u003Cp>The catalog date is January 1, 2017, but when and how the file was assembled remains uncertain, with conflicting claims pointing to 2014 and 2017. The file had circulated since at least October 2018 and was redistributed more broadly in May 2020. A separate blogging service observed account takeovers associated with these passwords, and contacted users confirmed they had previously used the affected passwords on LiveJournal. This evidence supports treating the passwords as compromised, but it does not conclusively prove that every record came directly from LiveJournal systems.\u003C\u002Fp>\u003Ch2>User Groups at Risk\u003C\u002Fh2>\u003Cp>People who reused an old LiveJournal password on email, social media, forum, or work accounts face the greatest risk. Reusing the same email address and username across platforms also increases the risk of profile matching, targeted phishing, and abuse of account-recovery processes.\u003C\u002Fp>\u003Ch2>Immediate Steps to Take\u003C\u002Fh2>\u003Cp>Treat every password previously used on LiveJournal as compromised. Create unique new passwords on any other account that used the same or a similar password, prioritizing email and accounts that can reset other credentials. Enable two-step verification where supported and close unfamiliar sessions.\u003C\u002Fp>\u003Ch2>Long-Term Security Strategies\u003C\u002Fh2>\u003Cp>Use a password manager to generate a different password for every service and review old blogging, forum, and social-network accounts regularly. Close accounts you no longer use, reduce unnecessary public profile links, and keep recovery email addresses and verification methods current.\u003C\u002Fp>\u003Ch2>Check Your Data\u003C\u002Fh2>\u003Cp>Check this record with email addresses you previously used for LiveJournal. A match shows that the address appears in the circulated file; it does not by itself prove that every row came directly from the platform. Even so, if there is a match, replace all old LiveJournal passwords and secure every account where they were reused.\u003C\u002Fp>","","LiveJournal Data Breach (26.4 Million Reported Records)","LiveJournal Data Breach. 26.4 Million reported records were reported. Reported data: Email addresses, Passwords, Usernames. Review the scope, risks, and…","\u002Fuploads\u002Flogo\u002Flivejournal_com.webp",false,{"name":7,"sector":38,"country":39,"website":10,"websiteArchiveUrl":32,"websiteStatus":32,"websiteCheckedAt":24},"Social Media","Russia"]