[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fjg8hz20jxf9r":3},{"success":4,"breach":5},true,{"_id":6,"name":7,"title":8,"slug":9,"domain":10,"breachDate":11,"addedDate":12,"modifiedDate":13,"contentUpdatedAt":13,"source":14,"sourceUrl":15,"sourceUrls":16,"pwnCount":17,"affectedCount":17,"affectedCountStatus":18,"affectedCountLowerBound":19,"affectedCountUnit":20,"hasEnglishDescription":4,"severity":21,"dataClasses":22,"description":29,"seoTitle":15,"seoTitleEn":30,"seoDescription":15,"seoDescriptionEn":31,"logoUrl":32,"isVerified":4,"isSensitive":33,"isSpamList":33,"isMalware":33,"company":34},"68e3266eda11adda4882532c","proctor-u","ProctorU 2020 Data Breach","proctoru","proctoru.com","2020-06-26T00:00:00.000Z","2020-08-06T09:37:17.000Z","2026-07-21T16:35:50.258Z","Verified breach record","",[],444453,"known",null,"unknown","High",[23,24,25,26,27,28],"Email addresses","Names","Passwords","Phone numbers","Physical addresses","Usernames","\u003Cp>The ProctorU 2020 data breach concerns user information associated with an online examination service that was obtained by unauthorized parties in June 2020 and later circulated in criminal online communities. The incident was reported to contain 444,453 user records. The affected data categories are email addresses, names, usernames, phone numbers, physical addresses, and password values transformed with bcrypt.\u003C\u002Fp>\n\u003Cp>That number does not represent the full user base or establish that every field was present for every person. The reported password values were not presented as plain-text passwords. Even so, reuse of the same password or a close variation on another service can create an account-takeover risk. The combination of contact details and sign-in information also warrants attention for phishing and targeted fraud.\u003C\u002Fp>\n\u003Ch2>Exposed Data Types and Risks\u003C\u002Fh2>\n\u003Cp>An email address, name, username, phone number, and physical address can make an unsolicited contact appear more credible. These details can support fake examination notices, account-check requests, or messages that resemble an institutional announcement. The presence of phone and address details can make a phishing attempt more convincing than an email-only approach.\u003C\u002Fp>\n\u003Cp>Although bcrypt transforms password values, password reuse remains important. If the same password or an easy-to-guess variation was used on another service, an attacker may attempt access to that account. Usernames can also make targeted sign-in attempts easier. The main risk is not one field in isolation, but the potential use of contact and sign-in information together.\u003C\u002Fp>\n\u003Ch2>Verified Scope and Limits\u003C\u002Fh2>\n\u003Cp>The incident date is recorded as June 26, 2020. The reported scale is 444,453 user records. This figure does not establish that users experienced financial loss or that every record held every listed field. The known data categories describe fields associated with the incident; individual notices or file contents are not available for every person.\u003C\u002Fp>\n\u003Cp>Public reporting on the incident states that the data was later shared widely. That means old passwords and contact details can remain useful in later phishing attempts. The technical entry method and the current use of every affected account are not established. This page therefore relies only on the verified date, reported scale, and known data categories.\u003C\u002Fp>\n\u003Ch2>Users at Elevated Risk\u003C\u002Fh2>\n\u003Cp>People who created an account for an online examination, provided account details, or used communication channels connected with ProctorU are the priority group. Former users should also consider the incident if they still use the same email address, username, or a similar password on other services. Completing an examination does not remove the risk that old account information could be reused.\u003C\u002Fp>\n\u003Cp>People who reused the same password for email, education services, social networks, or financial services should act promptly. A name combined with phone and physical address details can make targeted calls and fake support messages more persuasive. Even without a direct notice, someone who remembers using the service should review sign-in settings and contact accounts.\u003C\u002Fp>\n\u003Ch2>Immediate Protective Actions\u003C\u002Fh2>\n\u003Cp>The first step is to replace any password that was reused with ProctorU or a similar service. The email account should take priority because password-reset links for other accounts often arrive there. Enable multi-factor sign-in where available, close active sessions, and remove unfamiliar devices from accounts.\u003C\u002Fp>\n\u003Cp>Be careful with unexpected emails, messages, or calls requesting information under the pretext of examination results, account checks, fees, documents, or urgent action. It is safer to sign in directly through a known service address rather than use a link in a message. If an account shows an unusual sign-in alert, password-reset request, or profile change, use the relevant service's security channel without delay.\u003C\u002Fp>\n\u003Ch2>Long-Term Security Practices\u003C\u002Fh2>\n\u003Cp>The lasting risk from older breaches often comes from password reuse and the use of personal details in new fraud scenarios. A password manager, a different password for every account, and multi-factor sign-in reduce that risk. Review recovery options, forwarding rules, and connected devices in the email account at regular intervals.\u003C\u002Fp>\n\u003Cp>People whose contact details may be involved should verify unfamiliar offers, files, payment requests, or document requests through an independent channel. Limiting phone and address details held by unnecessary profiles, closing or updating old accounts, and reviewing privacy settings can reduce exposure. For a suspicious event, retain the date, sender, screenshot, and transaction details to support later reporting.\u003C\u002Fp>\n\u003Ch2>Record Check and User Action\u003C\u002Fh2>\n\u003Cp>The check on this page helps a person evaluate a possible connection with the ProctorU 2020 incident. A match does not mean that every data type was obtained for that person. When a match appears, review accounts connected with the email address first, then reused passwords and communication channels.\u003C\u002Fp>\n\u003Cp>Next steps should follow the data type: sign-in security for passwords and usernames; phishing precautions for email and phone details; and care with unexpected correspondence or delivery notices for physical addresses. The ProctorU 2020 incident shows why an older breach can still matter today when password reuse and targeted contact attempts remain possible.\u003C\u002Fp>","ProctorU 2020 Data Breach (444.5 Thousand Reported Records)","ProctorU 2020 Data Breach. 444.5 Thousand reported records were reported. Reported data: Email addresses, Names, Passwords. Review the scope, risks, and…","\u002Fuploads\u002Flogo\u002Fproctoru_com.webp",false,{"name":35,"sector":36,"country":37,"website":10,"websiteArchiveUrl":15,"websiteStatus":15,"websiteCheckedAt":19},"ProctorU","Education","United States"]