[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f1p16opxsl5jci":3},{"success":4,"breach":5},true,{"_id":6,"name":7,"title":8,"slug":9,"domain":10,"breachDate":11,"addedDate":12,"modifiedDate":13,"contentUpdatedAt":14,"source":15,"sourceUrl":16,"sourceUrls":17,"pwnCount":19,"affectedCount":19,"affectedCountStatus":20,"affectedCountLowerBound":21,"affectedCountUnit":22,"hasEnglishDescription":4,"severity":23,"dataClasses":24,"description":31,"seoTitle":32,"seoTitleEn":33,"seoDescription":32,"seoDescriptionEn":34,"logoUrl":35,"isVerified":4,"isSensitive":36,"isSpamList":36,"isMalware":36,"company":37},"68e3266eda11adda48825323","Poshmark","Poshmark Data Breach","poshmark","poshmark.com","2018-05-16T00:00:00.000Z","2019-09-02T03:36:05.000Z","2019-09-02T03:44:37.000Z","2026-07-18T23:56:19.932Z","Verified breach record","https:\u002F\u002Fblog.poshmark.com\u002F2019\u002F08\u002F01\u002Fimportant-security-notice-from-poshmark\u002F",[16,18],"https:\u002F\u002Ftechcrunch.com\u002F2019\u002F08\u002F01\u002Fposhmark-confirms-data-breach\u002F",36395491,"known",null,"unknown","Critical",[25,26,27,28,29,30],"Email addresses","Genders","Geographic locations","Names","Passwords","Usernames","\u003Cp>The Poshmark data breach is associated with the unauthorized access to user account information on the social commerce marketplace focused on buying and selling fashion products in mid-2018. The verified query set contains 36,395,491 accounts. The leaked fields include email addresses, names, usernames, gender information, geographic locations, and passwords protected with bcrypt. Storing passwords with a strong hashing method reduces risk; however, if the same password is reused on other services or if attackers used profile information for phishing, user security could still be affected.\u003C\u002Fp>\n\u003Ch2>Leaking Data Types and Risks\u003C\u002Fh2>\n\u003Cp>The types of data confirmed in the Poshmark leak are email addresses, name information, usernames, gender information, geographic location, and passwords. The fact that an email address is seen together with a username makes it easier for attackers to search for the account on different platforms. Location data, such as name, gender, and city, can make fake support messages, shopping notification imitations, and scam attempts under the pretext of delivery more convincing.\u003C\u002Fp>\n\u003Cp>Even though passwords are protected with bcrypt hashes, the risk does not disappear entirely. Weak or reused passwords can be subject to account takeover attempts when combined with different leaks. Additionally, on social shopping platforms like Poshmark, when usernames, profile information, and shopping interests are combined, the risks of targeted phishing, fake sales messages, fake return notifications, and non-payment social engineering increase.\u003C\u002Fp>\n\u003Ch2>Verified Scope and Boundaries\u003C\u002Fh2>\n\u003Cp>The violation date is tracked as May 2018 and the incident was announced in 2019. The verified account set contains 36,395,491 user records. Notifications related to the incident indicated that financial information and physical address details were not affected; however, important areas for account security such as user profiles, emails, city information, preference information, and password hashes were affected.\u003C\u002Fp>\n\u003Cp>The data classes on this page are limited according to the verifiable main account set: email addresses, gender information, geographic locations, names, passwords, and usernames. Details that are not confirmed to apply to each account are not presented as main data fields. This way, the user can clearly see which account security steps they need to take instead of an unnecessary or exaggerated risk explanation.\u003C\u002Fp>\n\u003Ch2>User Groups at Risk\u003C\u002Fh2>\n\u003Cp>Buyers with a Poshmark account, sellers, users who shop using their social profile, and people who use the same username on multiple platforms are the main risk group. For sellers who have a marketplace account, a combination of username, city, profile information, and email can be used in messages through fake orders, fake support requests, or account verification pretexts. For buyers, phishing attempts themed around discounts, returns, shipping, and account security stand out.\u003C\u002Fp>\n\u003Cp>People who use the same password on different shopping sites or email accounts are at higher risk. Even if password hashes are strong, attackers can initiate guessing attempts by matching the same email and username with other data sets. For users who have linked their social media account to their Poshmark profile, the risk of personal profile matching and fake messages may increase even more.\u003C\u002Fp>\n\u003Ch2>Urgent Measures to Be Taken\u003C\u002Fh2>\n\u003Cp>Password changes should be immediately made on all accounts that use the same or a similar password as Poshmark. The new password should be unique, long, and random; it should be stored with a password manager. Priority should be given to the email account, other shopping platforms, social media accounts, and services that contain payment information. Simply choosing the old password with small modifications does not provide sufficient protection.\u003C\u002Fp>\n\u003Cp>Multi-factor authentication should be enabled on accounts that support it. For Poshmark and similar marketplace accounts, registered email, session history, linked social media accounts, notification preferences, and profile information should be checked. In messages that come under the pretext of shipping, returns, seller verification, payment issues, or account security, the domain should be checked before clicking any link. If a suspicious session or unexpected password reset notification is observed, sessions should be terminated and the password should be renewed.\u003C\u002Fp>\n\u003Ch2>Long-Term Security Strategies\u003C\u002Fh2>\n\u003Cp>The Poshmark incident shows that shopping and social marketplace accounts should be evaluated not only with payment information but also with profile matching and phishing risks. Users should use different passwords for shopping, social media, email, and financial accounts; they should prefer separate email addresses whenever possible. Not leaving unnecessary personal information on the profile and regularly reviewing social account connections reduces long-term risk.\u003C\u002Fp>\n\u003Cp>For individuals with a seller account, the brand name, city, username, and communication channels may be more visible. Therefore, a standard habit of checking against phishing attempts coming through support messages, product links, and buyer communication is necessary. On the corporate side, leaked password monitoring and security training that prevent employees from reusing their personal shopping account passwords on work accounts provide lasting protection.\u003C\u002Fp>\n\u003Ch2>Record Control and User Action\u003C\u002Fh2>\n\u003Cp>If a Poshmark result appears in the account security check, it means the associated email address is included in the verified account set linked to the 2018 Poshmark data breach. This result does not mean that your current Poshmark account has been compromised today; however, it indicates that the email, username, profile information, and password hash used in the past may have been misused. If the same password has been used on other accounts, action should not be delayed.\u003C\u002Fp>\n\u003Cp>The first step is to secure your email account, then update all accounts that use the same or similar password. If there is a suspicious login, unrecognized device, unexpected sale message, fake support request, or password reset notification, a security check should be initiated on the relevant account. Completely eliminating password reuse, enabling multi-factor authentication, and making it a habit to check domain names in marketplace messages are the most effective user actions for Poshmark outcomes.\u003C\u002Fp>","","Poshmark Data Breach (36.4 Million Reported Records)","Poshmark Data Breach. 36.4 Million reported records were reported. Reported data: Email addresses, Genders, Geographic locations. Review the scope, risks, and…","\u002Fuploads\u002Flogo\u002Fposhmark_com.webp",false,{"name":7,"sector":38,"country":39,"website":10,"websiteArchiveUrl":32,"websiteStatus":32,"websiteCheckedAt":21},"Social commerce marketplace","United States"]