[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f2e73z4170xzw4":3},{"success":4,"breach":5},true,{"_id":6,"name":7,"title":8,"slug":9,"domain":10,"breachDate":11,"addedDate":12,"modifiedDate":12,"contentUpdatedAt":13,"source":14,"sourceUrl":15,"sourceUrls":16,"pwnCount":21,"affectedCount":21,"affectedCountStatus":22,"affectedCountLowerBound":23,"affectedCountUnit":24,"hasEnglishDescription":4,"severity":25,"dataClasses":26,"description":32,"seoTitle":33,"seoTitleEn":34,"seoDescription":33,"seoDescriptionEn":35,"logoUrl":36,"isVerified":4,"isSensitive":37,"isSpamList":37,"isMalware":37,"company":38},"68e3266eda11adda48825327","Promo","Promo Data Breach","promo","promo.com","2020-06-22T00:00:00.000Z","2020-07-26T02:44:11.000Z","2026-07-20T05:12:04.908Z","Third party breach","https:\u002F\u002Fsupport.promo.com\u002Fen\u002Farticles\u002F4276475-promo-data-breach-july-21-2020-faq",[15,17,18,19,20],"https:\u002F\u002Fpromo.com\u002F","https:\u002F\u002Fpromo.com\u002Fabout","https:\u002F\u002Fpromo.com\u002Fterms-of-service","https:\u002F\u002Fpromo.com\u002Fimages\u002FpromoVideos\u002Flogo.svg",14610585,"known",null,"unknown","Critical",[27,28,29,30,31],"Email addresses","Genders","IP addresses","Names","Passwords","\u003Cp>The June 22, 2020 \u003Cstrong>Promo data breach\u003C\u002Fstrong> affected 14,610,585 unique email addresses across 22 million records.\u003C\u002Fp>\u003Ch2>Types of Exposed Data and Risks\u003C\u002Fh2>\u003Cp>The verified data set contained email addresses, genders, IP addresses, names, and passwords. The company notice describes first and last name, email, approximate location derived from an IP address, gender, and an encrypted, hashed, and salted password for a Promo or Slidely account. Passwords were not plaintext; the canonical record identifies salted SHA-256 hashes. \u003Cstrong>Salted SHA-256 password hashes\u003C\u002Fstrong> are not directly readable, but they do not remove offline-guessing risk for short, common, or reused credentials. Combining a name, email, gender, IP address, and approximate location can support targeted phishing, fake video-subscription notices, and account-recovery abuse. Financial data, credit cards, and billing information were not stored on company servers and are outside the verified scope.\u003C\u002Fp>\u003Ch2>Breach Timeline and Technical Details\u003C\u002Fh2>\u003Cp>The canonical incident date is June 22, 2020; the Promo team said it became aware of the issue on July 21, 2020. The company reported that a vulnerability in a third-party service caused a breach affecting non-financial Promo and Slidely user data. It said suspicious activity was stopped, the vulnerable service was removed, a company investigation began, and external security specialists were retained. The data was later shared extensively on a hacking forum. Approximately 22 million total records contained 14,610,585 unique email addresses, so total rows and unique affected addresses are different measures. The company notified potentially affected customers and required users to change their Promo or Slidely password at the next login. The notice does not identify the vulnerable product or technical flaw, so a specific component or attack technique should not be presented as confirmed.\u003C\u002Fp>\u003Ch2>User Groups at Risk\u003C\u002Fh2>\u003Cp>The most directly affected group includes video creators, small businesses, marketing teams, agency employees, and former users with a Promo.com or earlier Slidely account in 2020. External social-platform passwords were not affected for people signing in through social media, although a separately created Promo or Slidely password hash may still have appeared. Approximate location derived from an IP address is not a precise street address and does not identify a person alone; combined with name, email, and gender, it can make targeted messages more convincing. Anyone who reused the password on primary email, social media, video sharing, advertising, cloud storage, or payment accounts faces higher credential-stuffing risk. An unused Slidely or Promo account may still create current exposure through its historical password and email. Marketing employees using corporate addresses should be cautious with fake campaign, renewal, and video-sharing invitations.\u003C\u002Fp>\u003Ch2>Immediate Steps to Take\u003C\u002Fh2>\u003Cp>If your Promo account remains active, navigate directly to the official site, set a unique password, and enable multi-factor authentication if supported. If you used the same or a similar Promo or Slidely password elsewhere in 2020, change those accounts immediately, prioritizing primary email, social media, cloud storage, advertising, and payment services. Use a password manager to generate a long, random password for every account. Review Promo sessions, connected social accounts, recovery email, and profile information; remove changes you do not recognize. For password-reset, video-sharing, subscription-renewal, or payment-problem messages, inspect the sender domain and destination link. Open promo.com yourself instead of signing in through a message and never disclose a one-time code. Financial data is outside the exposure, but fake invoices can use leaked profile context, so confirm payment requests independently.\u003C\u002Fp>\u003Ch2>Long-Term Security Strategies\u003C\u002Fh2>\u003Cp>Durable protection does not end with changing the Promo password. \u003Cstrong>Password reuse\u003C\u002Fstrong> allows an attacker who guesses a protected hash to test the same credential against other services, so use a unique password everywhere. Treat email as the recovery hub for other accounts and secure it with a strong password and preferably hardware-key authentication. Marketing teams should keep video creation, social media, advertising, cloud storage, and payment accounts on separate credentials and avoid sharing personal passwords in team accounts. Close unused Slidely or Promo accounts, review connected-application permissions, and promptly remove access for people who leave the team. Minimize unnecessary profile fields and enable login alerts. Ongoing breach monitoring and awareness of video-campaign phishing can expose misuse that appears long after the incident.\u003C\u002Fp>\u003Ch2>Check Your Data\u003C\u002Fh2>\u003Cp>A Promo match through LeakData means the email address appears in the verified incident data set. It does not show that the account remains active, that all five data categories existed in your record, or that the password hash was cracked. If matched, recall the email and possible password patterns used for Promo or Slidely in 2020; never enter an actual password into a breach-search field. Identify current accounts that may share a similar password, replace those credentials with unique passwords, enable multi-factor authentication, and review session history. No match is not an absolute guarantee because another email may have been used, a record may be missing, or the password may have appeared elsewhere. Continue breach monitoring, watch unexpected login and reset alerts, and verify suspicious subscription or support messages through independently opened official channels.\u003C\u002Fp>","","Promo Data Breach (14.6 Million Reported Records)","Promo Data Breach. 14.6 Million reported records were reported. Reported data: Email addresses, Genders, IP addresses. Review the scope, risks, and protective…","\u002Fuploads\u002Flogo\u002Fpromo_com.webp",false,{"name":39,"sector":40,"country":41,"website":10,"websiteArchiveUrl":33,"websiteStatus":33,"websiteCheckedAt":23},"Promo.com","Video creation and marketing technology","Israel"]