[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f15ahqi1kf4p1g":3},{"success":4,"breach":5},true,{"_id":6,"name":7,"title":8,"slug":9,"domain":10,"breachDate":11,"addedDate":12,"modifiedDate":13,"contentUpdatedAt":14,"source":15,"sourceUrl":16,"sourceUrls":17,"pwnCount":21,"affectedCount":21,"affectedCountStatus":22,"affectedCountLowerBound":23,"affectedCountUnit":24,"hasEnglishDescription":4,"severity":25,"dataClasses":26,"description":35,"seoTitle":36,"seoTitleEn":37,"seoDescription":36,"seoDescriptionEn":38,"logoUrl":39,"isVerified":4,"isSensitive":40,"isSpamList":40,"isMalware":40,"company":41},"68e3266eda11adda4882529c","Mashable","Mashable Data Breach","mashable","mashable.com","2020-06-01T00:00:00.000Z","2020-11-10T04:33:56.000Z","2020-11-10T04:56:58.000Z","2026-07-18T23:53:59.516Z","Digital media breach","https:\u002F\u002Fportswigger.net\u002Fdaily-swig\u002Fdata-breach-at-mashable-leaks-users-nbsp-personal-information-online",[16,18,19,20],"https:\u002F\u002Fwww.infosecurity-magazine.com\u002Fnews\u002Fmashable-customer-data-leaked\u002F","https:\u002F\u002Fmashable.com\u002F","https:\u002F\u002Fdehashed.com\u002F",1414677,"known",null,"unknown","Critical",[27,28,29,30,31,32,33,34],"Auth tokens","Email addresses","Genders","Geographic locations","IP addresses","Names","Partial dates of birth","Social media profiles","\u003Cp>The Mashable data breach is a verified account and profile data incident that affected 1,414,677 unique email addresses on the digital media and news platform, occurring in mid-2020 and publicly revealed in November 2020. The types of data recorded include authentication tokens, email addresses, gender information, geographic locations, IP addresses, names, partial birth date information, and social media profiles. This incident should not be treated as a password leak; passwords or payment cards are not among the verified fields. The risk is more centered around social session links, profile matching, targeted phishing, and privacy loss.\u003C\u002Fp>\n\u003Cp>For users who use the Mashable account or social media login feature, the most important point is that the leaked tokens are indicated as expired. This information directly prevents claiming current session access; nevertheless, the presence of tokens, combined with email, IP, location, and social profile links, can allow a detailed profile of the user to be created. Fields such as name, gender, birth date, and month information can make attackers' fake media subscription, account verification, or social network connection-themed messages more convincing.\u003C\u002Fp>\n\u003Ch2>Leaking Data Types and Risks\u003C\u002Fh2>\n\u003Cp>Email addresses in the Mashable record can be used for phishing messages themed around fake security alerts, media account warnings, subscription renewals, or social network connections. Information such as name, gender, and partial date of birth makes these messages appear personalized. IP addresses and geographic location fields do not indicate a full address, but they can provide hints about the user's general connection area or profile context. Social media profile links, on the other hand, can lead to connections with the user's broader online identity.\u003C\u002Fp>\n\u003Cp>Authentication tokens are the area of this record that needs to be handled most carefully. Verified information indicates that the tokens have expired; therefore, the statement that the current session has been compromised should not be used definitively. Nevertheless, the token history shows that a feature using social login may have been at risk. When social profile links and email addresses are used together, fake support messages, account security alerts, and personalized phishing attempts can become more effective.\u003C\u002Fp>\n\u003Ch2>Verified Scope and Boundaries\u003C\u002Fh2>\n\u003Cp>The verified scope consists of 1,414,677 unique email addresses, a breach date of June 1, 2020, an addition date of November 10, 2020, and eight types of data: authentication tokens, email addresses, genders, geographic locations, IP addresses, names, partial birth dates, and social media profiles. The partial birth date information is at the day and month level; it should not be described as a full birth date. Password, phone number, physical address, payment card, bank account, or official ID document do not appear as verified fields in the record.\u003C\u002Fp>\n\u003Cp>For this record, the distinction between data leakage and direct account takeover should be maintained. Expired token information indicates the risk of an old social session or login link; however, it should not be concluded that current session keys are still usable. The main risks communicated to the user should revolve around social profile matching, targeted phishing, privacy loss, personalized fake messages using name and location context, and misuse of the email address.\u003C\u002Fp>\n\u003Ch2>User Groups at Risk\u003C\u002Fh2>\n\u003Cp>The users at the highest risk are those who have linked their Mashable account with social media profiles and use the same email address for multiple media or social network accounts. Users with open social profile links may be targeted with fake share alerts, fake copyright notices, subscription notifications, or account security messages. Partial birth date, name, and gender information help make these messages appear more personal.\u003C\u002Fp>\n\u003Cp>The risk of profile matching is more pronounced for individuals with publicly accessible social media profiles. IP and geographic location information alone do not provide a complete address, but they can give clues about the user's general area or connection habits. People who use their work email alongside social media logins should also exercise extra caution; because if personal media account information is combined with their work identity, fake business notifications or brand communication-themed attacks can become more convincing.\u003C\u002Fp>\n\u003Ch2>Urgent Measures to Be Taken\u003C\u002Fh2>\n\u003Cp>If you see a match in the Mashable record, first check your affected email address and the social media accounts associated with this address. Even if there is no password-verified data field, if you used social login, review the app permissions and active sessions in the connected accounts. Enable two-factor authentication on your email account, check recovery addresses, and terminate unknown sessions. Keep security alerts enabled on media, social network, and subscription accounts that you use with the same email.\u003C\u002Fp>\n\u003Cp>Do not click directly on links coming under the name of Mashable or a media account; open the domain yourself to check the account. Do not respond to messages requesting social media access, recovery codes, additional security information, or payment information. Messages that contain personalized details such as name, partial date of birth, or location information may appear more convincing; therefore, even if the content of the message carries correct personal information, it should not be assumed that the request is legitimate.\u003C\u002Fp>\n\u003Ch2>Long-Term Security Strategies\u003C\u002Fh2>\n\u003Cp>For long-term protection, accounts used for social entry should be reviewed at regular intervals. The list of applications linked to social media accounts should be cleaned, unused application permissions should be removed, and separate security settings should be maintained for media accounts. The main email address can be used for critical accounts, while media and subscription accounts can be used with a lower-risk separate email address. This distinction makes it harder for a single media account breach to spread to the entire digital identity.\u003C\u002Fp>\n\u003Cp>The name, location, birthday, and social connections visible on the profile should be reduced if unnecessary. Users should be aware that keeping their social media profiles public can increase the risk of targeted messages. Regular account checks, two-factor authentication, clearing social login permissions, and email security habits provide lasting protection after such breaches. Even if it was an old breach, the same email and social profile links can be used in phishing campaigns years later.\u003C\u002Fp>\n\u003Ch2>Record Control and User Action\u003C\u002Fh2>\n\u003Cp>If you see a match in the Mashable breach, first list your social media and media accounts linked to the affected email address. Then check open sessions, connected app permissions, recovery options, and security alerts on these accounts. If the same email address is also used on work or critical personal accounts, make sure two-factor authentication and recovery information are up to date for these accounts. Reducing your social profile links lowers the risk of future profile matching.\u003C\u002Fp>\n\u003Cp>This record should not be considered a password, phone, physical address, or payment card leak; the verified risk comes from a combination of email, name, gender, partial birth date, IP, geographic location, social profile, and expired tokens. Although the Mashable breach dates back to 2020, this information can still be used in targeted messages today. The most appropriate action is to secure the email account strongly, clean up social login permissions, and be cautious of fake media notifications containing personal information.\u003C\u002Fp>","","Mashable Data Breach (1.4 Million Reported Records)","Mashable Data Breach. 1.4 Million reported records were reported. Reported data: Auth tokens, Email addresses, Genders. Review the scope, risks, and…","\u002Fuploads\u002Flogo\u002Fmashable_com.webp",false,{"name":7,"sector":42,"country":43,"website":10,"websiteArchiveUrl":36,"websiteStatus":36,"websiteCheckedAt":23},"Digital Media \u002F News","United States"]