[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f23xals06mhb3y":3},{"success":4,"breach":5},true,{"_id":6,"name":7,"title":8,"slug":9,"domain":10,"breachDate":11,"addedDate":12,"modifiedDate":12,"contentUpdatedAt":13,"source":14,"sourceUrl":15,"sourceUrls":16,"pwnCount":18,"affectedCount":18,"affectedCountStatus":19,"affectedCountLowerBound":20,"affectedCountUnit":21,"hasEnglishDescription":4,"severity":22,"dataClasses":23,"description":29,"seoTitle":30,"seoTitleEn":31,"seoDescription":30,"seoDescriptionEn":32,"logoUrl":33,"isVerified":34,"isSensitive":34,"isSpamList":34,"isMalware":34,"company":35},"68e3266eda11adda4882533c","ReadNovel","Read Novel Alleged Data Exposure","read-novel","readnovel.com","2019-05-01T00:00:00.000Z","2022-05-16T08:41:14.000Z","2026-07-19T17:33:43.958Z","Unverified third-party dataset attributed to Read Novel","https:\u002F\u002Fwww.troyhunt.com\u002Fhandling-chinese-data-breaches-in-have-i-been-pwned\u002F",[15,17],"https:\u002F\u002Freadnovel.com\u002F",22424472,"known",null,"email_identifiers","Critical",[24,25,26,27,28],"Email addresses","Genders","Passwords","Phone numbers","Usernames","\u003Cp>\u003Cstrong>The Read Novel breach record\u003C\u002Fstrong> describes an unverified dataset attributed to readnovel.com that contains 22,424,472 accounts.\u003C\u002Fp>\u003Ch2>Types of Exposed Data and Risks\u003C\u002Fh2>\u003Cp>The confirmed fields in the dataset are email addresses, usernames, phone numbers, gender, and passwords stored as salted MD5 hashes. Salting makes it harder for identical passwords to produce identical hashes, but MD5 is fast and weak by modern password-storage standards. Short, common, or reused passwords may therefore be recovered through offline guessing. Combining an email address, username, and phone number supports account matching, targeted text messages, phishing, and abuse of password-reset workflows. Gender does not provide account access by itself, but it may add context to personalized fraud. \u003Cstrong>Because the complete dataset was not conclusively verified as originating from Read Novel systems, this record must not be presented as a confirmed company breach.\u003C\u002Fstrong> Evidence of genuine account data still makes eliminating password reuse an appropriate precaution.\u003C\u002Fp>\u003Ch2>Breach Timeline and Technical Details\u003C\u002Fh2>\u003Cp>The dataset was associated with an alleged event in May 2019. The May 1 date shown in this record is a normalized month-level date; it must not be interpreted as a confirmed day of intrusion, initial access, or data removal. The record was later added to a public breach catalogue in 2022. Review found the fields and account volume consistent enough to represent a security risk, but no reliable incident notice from Read Novel or its owner, Yuewen Group, was located. The responsible actor, access method, affected systems, and discovery date could not be verified and are not asserted. The reliable technical detail is that the password field contained salted MD5 hashes. The record keeps evidence of real credential risk visible while preserving uncertainty about company attribution and maintaining its unverified status.\u003C\u002Fp>\u003Ch2>User Groups at Risk\u003C\u002Fh2>\u003Cp>People who used accounts on readnovel.com or related Read Novel online-literature services in or before 2019 are the most relevant risk group. Even when an old email address or phone number is no longer active, a password reused on a current service can keep the risk alive. A username and email combination can help locate accounts on other forums, reading applications, or social platforms, while a phone number can support fake membership renewals, verification-code requests, premium-content offers, or payment alerts. Weak passwords are especially exposed because MD5 hashes can be tested quickly. For someone who does not remember creating a Read Novel account, a match does not prove attribution; forgotten membership, reuse of the same username elsewhere, or incorrect labeling of a dataset remain possible. Uncertainty does not remove the need for precautions, but it does prevent a definitive incident narrative.\u003C\u002Fp>\u003Ch2>Immediate Steps to Take\u003C\u002Fh2>\u003Cp>If the password used with the matched email or username around 2019 can be remembered, replace the same or similar password on every current account. Do not type the old password into a breach-checking form or unknown website; use each service's official password-reset page. \u003Cstrong>Create a long, unique password for every account and enable multifactor authentication, beginning with the email account.\u003C\u002Fstrong> Review active email sessions, recovery addresses, and trusted devices, then close unfamiliar access. If the phone number is still active, consider an additional carrier PIN and alerts for unauthorized SIM changes. Do not follow inbound links that appear to offer Read Novel premium content, subscription renewal, or account verification; open the known site or application independently. Exposure of a phone number does not establish device compromise, so it should not be used as evidence of malware without other indicators.\u003C\u002Fp>\u003Ch2>Long-Term Security Strategies\u003C\u002Fh2>\u003Cp>A password manager, randomly generated credentials for every service, and a strong second factor on the primary email account reduce the lasting danger from old credentials. Periodically close unused reading, forum, and community accounts, and review whether profiles retain unnecessary phone or demographic information. Reusing the same username across many services makes account linkage easier, so separate identifiers may be appropriate for sensitive and public accounts. Service providers should avoid fast hashes such as MD5, use modern slow password-derivation functions with unique salts, protect sessions, and rate-limit unusual login attempts. For datasets of uncertain origin, account count, exposed fields, password format, company attribution, and verification level should remain separate properties. If a company disclosure or stronger technical evidence appears, the record should be reassessed instead of silently being treated as verified.\u003C\u002Fp>\u003Ch2>Check Your Data\u003C\u002Fh2>\u003Cp>A match may show that an email address appears in the 22,424,472-account dataset attributed to Read Novel; it does not prove that the person created a readnovel.com account or that the data came directly from those systems. Consider how the matched email, username, and phone number were used before 2019, then determine whether the password from that period was reused elsewhere. Never enter the password itself into a checking form; perform only secure password changes. Even if the old password is no longer active, review the email account's session history and recovery options. The 22,424,472 figure is the catalogue's account count, and not every account should be assumed to contain all five fields. Because attribution remains unverified, users should not be told a definitive intrusion day, method, or actor. Manage the risk through the salted MD5 password field and possible misuse of contact information.\u003C\u002Fp>","","Read Novel Alleged Data Exposure (22.4 Million Email Identifiers)","Read Novel Alleged Data Exposure. 22.4 Million email identifiers were reported. Reported data: Email addresses, Genders, Passwords. Review the scope, risks…","\u002Fuploads\u002Flogo\u002Freadnovel_com.webp",false,{"name":36,"sector":37,"country":38,"website":10,"websiteArchiveUrl":30,"websiteStatus":30,"websiteCheckedAt":20},"Yuewen Group (Read Novel)","Online Literature","China"]