[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f302uzfrksvs6n":3},{"success":4,"breach":5},true,{"_id":6,"name":7,"title":8,"slug":9,"domain":10,"breachDate":11,"addedDate":12,"modifiedDate":12,"contentUpdatedAt":13,"source":14,"sourceUrl":15,"sourceUrls":16,"pwnCount":21,"affectedCount":21,"affectedCountStatus":22,"affectedCountLowerBound":23,"affectedCountUnit":24,"hasEnglishDescription":4,"severity":25,"dataClasses":26,"description":34,"seoTitle":35,"seoTitleEn":36,"seoDescription":35,"seoDescriptionEn":37,"logoUrl":38,"isVerified":4,"isSensitive":39,"isSpamList":39,"isMalware":39,"company":40},"68e3266eda11adda48825289","LuminPDF","Lumin PDF Data Breach","lumin-pdf","luminpdf.com","2019-04-01T00:00:00.000Z","2019-09-18T05:00:15.000Z","2026-07-20T02:42:21.374Z","Database leak","https:\u002F\u002Fwww.zdnet.com\u002Farticle\u002Fdata-of-24-3-million-lumin-pdf-users-shared-on-hacking-forum\u002F",[15,17,18,19,20],"https:\u002F\u002Fwww.bankinfosecurity.com\u002Fluminpdf-leaked-exposed-data-for-243m-users-a-13100","https:\u002F\u002Fwww.luminpdf.com\u002Fblog\u002Fis-lumin-pdf-editor-safe","https:\u002F\u002Fwww.luminpdf.com\u002Fcompany\u002Fwho-we-are","https:\u002F\u002Fwww.luminpdf.com\u002Fterms-of-use",15453048,"known",null,"unknown","Critical",[27,28,29,30,31,32,33],"Auth tokens","Email addresses","Genders","Names","Passwords","Spoken languages","Usernames","\u003Cp>The April 2019 Lumin PDF data breach affected 15,453,048 accounts and exposed names, emails, usernames, genders, languages, passwords and auth tokens.\u003C\u002Fp>\u003Ch2>Types of Exposed Data and Risks\u003C\u002Fh2>\u003Cp>The verified dataset contained authentication tokens, email addresses, genders, names, passwords, spoken languages and usernames. \u003Cstrong>The 15,453,048 unique accounts\u003C\u002Fstrong> represent the deduplicated searchable corpus; the publicly shared archive was reported to contain approximately 24.3 million rows, so the two figures must not be used interchangeably. Most records contained an access token associated with Lumin PDF's Google Drive connection, while 118,746 direct Lumin accounts contained bcrypt password hashes. It must not be assumed that every row included both a password and a token. The company said the leaked Google tokens had expired at the time of the incident and could not provide access to user documents or signatures. That was a company assertion and was not independently verified by the reporting outlet.\u003C\u002Fp>\u003Ch2>Breach Timeline and Technical Details\u003C\u002Fh2>\u003Cp>In April 2019, a database belonging to Lumin PDF was reportedly left accessible on the internet without password protection and data was taken from it. In September 2019, user information became available for download on a criminal forum; journalists obtained a copy and checked its authenticity against several Lumin PDF users. After the initial report, Lumin PDF investigated and confirmed that the material contained a portion of its user data. \u003Cstrong>The exposed database held roughly 24.3 million rows, while the canonical deduplicated count is 15,453,048\u003C\u002Fstrong>. The company maintained that Google access tokens were invalid; the reporting outlet said it could not independently verify that claim and that Google was investigating. The precise exposure duration and whether every row was acquired at the same time were not established, so no additional mechanism should be inferred.\u003C\u002Fp>\u003Ch2>User Groups at Risk\u003C\u002Fh2>\u003Cp>People who created a direct Lumin PDF account with a password face account-takeover risk, especially if they reused that password on email or another service. Bcrypt slows offline guessing, but it cannot make short, common or previously breached passwords unguessable. For users who signed in with Google, risk depends on whether an access token was valid at the time and on the permissions it held. Although the company said the tokens had expired, reviewing third-party application access remains a prudent measure. Names, emails, usernames, genders and language settings can support convincing messages about document sharing, signature requests, invoices, collaboration invitations or account security. An email match does not prove that a password was recovered, a Google account was entered or any PDF document was viewed.\u003C\u002Fp>\u003Ch2>Immediate Steps to Take\u003C\u002Fh2>\u003Cp>If you registered directly with a Lumin PDF password, change it and update every other account using the same or a similar credential. \u003Cstrong>Protect the primary mailbox with a unique password and multi-factor authentication\u003C\u002Fstrong>, because most password resets arrive there. Open the third-party application permissions in your Google account, review the scope granted to Lumin PDF and remove access if you no longer use the service. If you continue using it, revoking the permission and reconnecting through the official application can help invalidate an older token. Review unfamiliar Google sessions, security events and connected devices. Do not follow unexpected links about shared documents, electronic signatures, invoices or storage limits; open Lumin PDF and Google Drive through their known domains. Never provide a password, access token or one-time code to a support caller or message.\u003C\u002Fp>\u003Ch2>Long-Term Security Strategies\u003C\u002Fh2>\u003Cp>Use a password manager to generate a long, unique credential for every service so recovery of one bcrypt hash cannot spread to other accounts. Prefer passkeys or phishing-resistant multi-factor authentication on email and cloud-storage services. Regularly review third-party application permissions in Google, Microsoft and similar accounts; remove unused connections and grant only the minimum required scopes. Inspect access settings, link permissions and collaborator lists for shared documents. Organizations should protect internet-facing databases with authentication, network allowlists and firewalls, keep backups behind separate access boundaries and perform external-asset scanning. OAuth tokens should use minimal privileges, short lifetimes and rotation, with a mechanism for bulk revocation after an incident. Do not trust a sender merely because they know a genuine filename or user detail.\u003C\u002Fp>\u003Ch2>Check Your Data\u003C\u002Fh2>\u003Cp>Use the secure search field on this page to check every current and historical email address you may have used with Lumin PDF. A match means the address appears among the 15,453,048 verified unique accounts; it does not reveal whether the row held a bcrypt password hash or Google access token, prove that a token was valid or show that documents were exposed. If you receive a result, determine whether you used a direct password, remove surviving password reuse and review third-party application access in the Google account. If you reused the same username elsewhere, remain alert to phishing and profile correlation. Never enter a password, access token, one-time code or document content into the search field. No result is an absolute guarantee because a different address, a record outside this dataset or another incident may still apply. Open the service's known domain directly instead of using links in suspicious document or signature alerts.\u003C\u002Fp>","","Lumin PDF Data Breach (15.5 Million Reported Records)","Lumin PDF Data Breach. 15.5 Million reported records were reported. Reported data: Auth tokens, Email addresses, Genders. Review the scope, risks, and…","\u002Fuploads\u002Flogo\u002Fluminpdf_com.webp",false,{"name":41,"sector":42,"country":43,"website":10,"websiteArchiveUrl":35,"websiteStatus":35,"websiteCheckedAt":23},"Lumin PDF","Document Management \u002F SaaS","New Zealand"]