[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f2xei7kq45wj2k":3},{"success":4,"breach":5},true,{"_id":6,"name":7,"title":8,"slug":9,"domain":10,"breachDate":11,"addedDate":12,"modifiedDate":13,"contentUpdatedAt":14,"source":15,"sourceUrl":16,"sourceUrls":17,"pwnCount":18,"affectedCount":18,"affectedCountStatus":19,"affectedCountLowerBound":20,"affectedCountUnit":21,"hasEnglishDescription":4,"severity":22,"dataClasses":23,"description":28,"seoTitle":16,"seoTitleEn":29,"seoDescription":16,"seoDescriptionEn":30,"logoUrl":31,"isVerified":4,"isSensitive":32,"isSpamList":32,"isMalware":32,"company":33},"68e3266eda11adda4882529b","ma-reads","MaReads Data Breach","mareads","mareads.com","2025-06-22T00:00:00.000Z","2025-07-15T07:13:20.000Z","2026-07-03T23:13:31.112Z","2026-07-18T23:53:57.838Z","Third party breach","",[],74453,"known",null,"unknown","Medium",[24,25,26,27],"Dates of birth","Email addresses","Phone numbers","Usernames","\u003Cp>The MaReads data breach is related to the platform for Thai language fiction and comic readers and writers exposing user registrations in the June 2025 period. The scope is approximately 74,453 records. This record was treated as a reading-writing community account breach; the company re-checked the fields of country, industry, website, and data class. The password field was not verified; the risk is in the combined use of communication and profile information.\u003C\u002Fp>\u003Cp>The text was rewritten to directly explain the risk and action to the user. The website field was kept as mareads.com; a protocol was not added, so a format that would cause https to appear twice on the link side was not used. The country was corrected from United States to Thailand, and the industry was corrected from general technology to a reading, fiction, and comic platform.\u003C\u002Fp>\u003Ch2>Leaking Data Types and Risks\u003C\u002Fh2>\u003Cp>The types of data seen in this record are email addresses, phone numbers, usernames, and dates of birth. Since there is no password field, it was not claimed that account passwords were compromised. Unverified payment cards, bank accounts, private messages, government IDs, health records, or additional profile fields were not added to the data class list; only the supported fields were retained.\u003C\u002Fp>\u003Cp>Phone number and date of birth can be used alongside the username in fake support, membership verification, or community notification messages. An email address alone creates a risk of unwanted messages; when combined with phone number, address, IP, date of birth, photo, ID number, or device tracking data, it becomes easier for an attacker to generate messages specific to the user. Therefore, the risk is evaluated not only based on the number of records but also on the combinability of the data.\u003C\u002Fp>\u003Ch2>Verified Scope and Boundaries\u003C\u002Fh2>\u003Cp>The scope was confirmed with record 74,453 dated June 2025. While the verified areas were retained, the unconfirmed areas were excluded. The incident was not combined with other brands, records with similar names, or events of the same company from different periods.\u003C\u002Fp>\u003Cp>The event was limited to the MaReads domain name and was not merged with other reading platforms. This approach prevents duplicate breaches from being added and shows the correct organizational responsibility to the user. The domain name, company name, and industry information were kept in the narrowest accurate context possible; in cases of uncertainty, a verified flag or website domain was set accordingly.\u003C\u002Fp>\u003Ch2>User Groups at Risk\u003C\u002Fh2>\u003Cp>User groups at risk are readers, authors, and community members who open a MaReads account. Matched users should also evaluate other accounts where they use the same email, phone, username, or password pattern outside of the relevant account.\u003C\u002Fp>\u003Cp>There may be a risk of identity matching for people who use their nickname in different communities. If there is corporate email, child or family account, public record, gaming identity, literacy community, monitoring software, or professional service context, the risk of social engineering may increase. Users should not consider details that appear accurate about themselves as a sign of trust.\u003C\u002Fp>\u003Ch2>Urgent Measures to Be Taken\u003C\u002Fh2>\u003Cp>Affected users should carefully check membership, work notification, or account verification messages received via phone and email. For records with a password field, all accounts using the same password should be updated; for records without a password field, the focus should be on the risks of phone, email, fake notifications, and identity matching.\u003C\u002Fp>\u003Cp>Instead of clicking on the links in the message, the address of the relevant service should be typed manually or the record in a trusted password manager should be used. Messages regarding cargo, support, game rewards, account warnings, public records, security notifications, document sharing, or subscription renewal should not be accepted without verification through an independent channel.\u003C\u002Fp>\u003Ch2>Long-Term Security Strategies\u003C\u002Fh2>\u003Cp>Optional fields like date of birth and phone number on community platforms should be kept to a minimum. Users should regularly clean up old accounts, unnecessary profile fields, duplicate usernames, old phone numbers, and address information. A unique password for each service and two-factor authentication wherever possible should be a basic rule.\u003C\u002Fp>\u003Cp>From the perspective of service providers, data minimization, strong password protection, monitoring of access logs, deletion of unnecessary fields, and readiness of user notification processes are necessary. Reading platforms should minimize birth date and phone data since it can also affect young users. Accurate scope explanation is also part of the security work; exaggerated or incomplete information can mislead the user to take the wrong action.\u003C\u002Fp>\u003Ch2>Record Control and User Action\u003C\u002Fh2>\u003Cp>The user should first check this record with their email address. If a match is found, it should be assumed that the phone number, date of birth, and username may be at risk, and community-themed messages should also be verified. Not finding a match does not completely rule out the use of a different email or the reuse of an old password; critical accounts should also be reviewed.\u003C\u002Fp>\u003Cp>This record remained verified; however, no claim regarding password or payment information was added. In this edit, data fields were left as English canonical classes, the description visible to the user was written in Turkish and original, unverified fields were not added, and the sensitivity flag was used only when supported by the risk context.\u003C\u002Fp>","MaReads Data Breach (74.5 Thousand Reported Records)","MaReads Data Breach. 74.5 Thousand reported records were reported. Reported data: Dates of birth, Email addresses, Phone numbers. Review the scope, risks, and…","\u002Fuploads\u002Flogo\u002Fmareads_com.webp",false,{"name":34,"sector":35,"country":36,"website":10,"websiteArchiveUrl":16,"websiteStatus":16,"websiteCheckedAt":20},"MaReads","Reading \u002F Thai Fiction and Comics Platform","Thailand"]