[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f2m9y38jqpypgp":3},{"success":4,"breach":5},true,{"_id":6,"name":7,"title":8,"slug":9,"domain":10,"breachDate":11,"addedDate":12,"modifiedDate":12,"contentUpdatedAt":13,"source":14,"sourceUrl":15,"sourceUrls":16,"pwnCount":19,"affectedCount":19,"affectedCountStatus":20,"affectedCountLowerBound":21,"affectedCountUnit":22,"hasEnglishDescription":4,"severity":23,"dataClasses":24,"description":33,"seoTitle":34,"seoTitleEn":35,"seoDescription":34,"seoDescriptionEn":36,"logoUrl":37,"isVerified":4,"isSensitive":38,"isSpamList":38,"isMalware":38,"company":39},"68e3266eda11adda48825298","MangaToon","MangaToon Data Breach","mangatoon","mangatoon.mobi","2022-05-13T00:00:00.000Z","2022-07-06T21:04:25.000Z","2026-07-19T16:47:02.580Z","Verified digital comics platform data breach","https:\u002F\u002Fwww.bleepingcomputer.com\u002Fnews\u002Fsecurity\u002Fmangatoon-data-breach-exposes-data-from-23-million-accounts\u002F",[15,17,18],"https:\u002F\u002Fwww.malwarebytes.com\u002Fblog\u002Fnews\u002F2022\u002F07\u002Finsecure-password-leads-to-mangatoon-data-exposure","https:\u002F\u002Fmangatoon.mobi\u002F",23040238,"known",null,"unknown","Critical",[25,26,27,28,29,30,31,32],"Auth tokens","Avatars","Email addresses","Genders","Names","Passwords","Social media profiles","Usernames","\u003Cp>The MangaToon data breach exposed identity and sign-in data from 23,040,238 accounts in May 2022. Records from the Hong Kong-based digital-comics platform included email addresses, names, usernames, gender data, avatars, social-media profiles, social-login tokens, and password hashes. The verified account scope is \u003Cstrong>23,040,238 subscriber records\u003C\u002Fstrong>. Phone numbers, physical addresses, payment cards, banking data, and government identity documents are not verified data classes for this incident.\u003C\u002Fp>\u003Ch2>Types of Exposed Data and Risks\u003C\u002Fh2>\u003Cp>Email addresses, names, and usernames can support targeted phishing or account-matching attempts, while gender data, avatars, and social-profile identities can make messages more personal. Passwords were confirmed to be stored as \u003Cstrong>salted MD5 hashes\u003C\u002Fstrong>. Salting prevents identical passwords from producing the same hash, but MD5 is not a modern, deliberately slow password-hashing algorithm, so weak passwords remain vulnerable to offline guessing. Authentication tokens obtained from social sign-ins are not passwords, and their validity periods were not disclosed, but tokens that were active when stolen could have created a separate session risk. The social-media-profile data class refers to account identities; it does not establish that private messages or social-network passwords were exposed.\u003C\u002Fp>\u003Ch2>Breach Timeline and Technical Details\u003C\u002Fh2>\u003Cp>The reference date for the incident is 13 May 2022. Technical reporting said the attacker accessed a MangaToon Elasticsearch server with an easily guessed credential and alleged that the password was literally “password.” The server credential was reportedly changed after the attacker notified the company, but multiple attempts to contact the company and obtain a response for users went unanswered. Account samples shared with a news organization were also checked and confirmed to be valid on the platform. More than 23 million records were added to a verified breach directory in July 2022. Public information does not establish how long the database was accessible, whether the tokens were active at the time, or whether every record contained every field, so those points should not be presented as certain.\u003C\u002Fp>\u003Ch2>User Groups at Risk\u003C\u002Fh2>\u003Cp>People who reused their MangaToon password elsewhere and users who signed in through a social account face the most direct risk. A recovered password can fuel credential-stuffing attempts against email, social-media, or other entertainment services that accept the same credentials. For users whose \u003Cstrong>social-login tokens\u003C\u002Fstrong> were present, changing a password alone may not be enough; connected-app permissions and active sessions also require review. Combining a name, email address, gender, avatar, and social-profile identity can make fake support messages or MangaToon-themed promotions more convincing. Not every field should be assumed to appear in all 23,040,238 records, and the tokens should not be assumed to remain valid today. Payment and physical-address data are outside the verified scope, so financial-fraud claims cannot be directly attributed to this incident.\u003C\u002Fp>\u003Ch2>Immediate Steps to Take\u003C\u002Fh2>\u003Cp>Replace the MangaToon password with a long, unique password and create separate credentials on every service where the same or a similar password was used. Enable multi-factor authentication on the associated email account and social-media account. If you used social sign-in, review the provider's connected-app list, revoke MangaToon access, consider reconnecting only through the official app or website, terminate existing sessions, and inspect unfamiliar sign-ins. Do not follow links in unexpected MangaToon-themed reset, free-token, membership, or content-unlock messages. If the profile email, username, avatar, or connected social account changed without permission, contact support through an official channel. Never enter a password or token value into a breach-search form or third-party website.\u003C\u002Fp>\u003Ch2>Long-Term Security Strategies\u003C\u002Fh2>\u003Cp>A password manager that generates a different password for every service prevents an old leak from spreading to other accounts. Social sign-in can be convenient, but connected-app lists should be cleaned periodically and unused sessions revoked. Because email is the recovery hub for many accounts, protect it with the strongest unique password and multi-factor authentication. If a MangaToon account is no longer needed, investigate deletion or closure through official channels. For service operators, durable protections include keeping management interfaces off the public internet, using strong unique service credentials, restricting network access, applying modern password hashing, limiting token lifetimes, monitoring anomalies, and running a clear incident-notification process.\u003C\u002Fp>\u003Ch2>Check Your Data\u003C\u002Fh2>\u003Cp>Search your email address in LeakData to see whether it matches the MangaToon breach record. Only query an address that belongs to you or that you are authorized to review. A match means the address appears in the verified dataset; it does not prove that the password was recovered, a social token remains valid, or the account was taken over. An empty result should not override a trusted security notice received through another channel. If there is a match, replace reused passwords first, then review connected social applications, active sessions, and account-recovery settings.\u003C\u002Fp>","","MangaToon Data Breach (23 Million Reported Records)","MangaToon Data Breach. 23 Million reported records were reported. Reported data: Auth tokens, Avatars, Email addresses. Review the scope, risks, and…","\u002Fuploads\u002Flogo\u002Fmangatoon_mobi.webp",false,{"name":7,"sector":40,"country":41,"website":10,"websiteArchiveUrl":34,"websiteStatus":34,"websiteCheckedAt":21},"Digital comics and manga","Hong Kong"]