[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f21xpvjuget9sw":3},{"success":4,"breach":5},true,{"_id":6,"name":7,"title":8,"slug":9,"domain":10,"breachDate":11,"addedDate":12,"modifiedDate":13,"contentUpdatedAt":13,"source":14,"sourceUrl":15,"sourceUrls":16,"pwnCount":18,"affectedCount":18,"affectedCountStatus":19,"affectedCountLowerBound":20,"affectedCountUnit":21,"hasEnglishDescription":4,"severity":22,"dataClasses":23,"description":28,"seoTitle":29,"seoTitleEn":30,"seoDescription":29,"seoDescriptionEn":31,"logoUrl":32,"isVerified":4,"isSensitive":4,"isSpamList":33,"isMalware":33,"company":34},"68e3266eda11adda48825365","ShareThis","ShareThis Data Breach","sharethis","sharethis.com","2018-07-09T00:00:00.000Z","2019-03-03T06:31:39.000Z","2026-07-27T16:11:14.487Z","Verified breach record","https:\u002F\u002Fwww.theregister.com\u002Fsecurity\u002F2019\u002F02\u002F11\u002F620-million-accounts-stolen-from-16-hacked-websites-now-for-sale-on-dark-web-seller-boasts\u002F665817",[15,17],"https:\u002F\u002Fattorneygeneral.delaware.gov\u002Fwp-content\u002Fuploads\u002Fsites\u002F50\u002F2019\u002F06\u002FShareThis-Consumer-Notice.pdf",40960499,"known",null,"unknown","Critical",[24,25,26,27],"Dates of birth","Email addresses","Names","Passwords","\u003Cp>The ShareThis data breach is a confirmed incident from July 2018 affecting user accounts of ShareThis, which provides social sharing tools and web content engagement services. The confirmed main scope is 40,960,499 unique email accounts. Although the incident became visible in an extensive wave of data sales at the beginning of 2019, the assessment for ShareThis should be directly limited to account data related to this service. The affected data groups are birth dates, email addresses, name information, and password hashes. Therefore, the risk is not limited only to old ShareThis accounts; if the same email or password was used on other services, the risk of account takeover, phishing, spam, and profile matching continues.\u003C\u002Fp>\n\u003Ch2>Leaking Data Types and Risks\u003C\u002Fh2>\n\u003Cp>Verified data categories include birth dates, email addresses, name information, and passwords. The password field should be treated as hashed password data, not as plain text passwords. A hashed password does not mean that the password is directly readable; however, weak, short, or reused passwords can be guessed by attackers. If the same password is also valid for email, social media, shopping, publisher accounts, or ad tool accounts, this breach can spread to other services.\u003C\u002Fp>\n\u003Cp>When combined with the email address, the date of birth and name information provides a strong basis for personalized fake messages for the user. Since ShareThis services are associated with websites, sharing tools, and the online marketing ecosystem, attackers can prepare messages themed around ad accounts, content tools, social sharing plugins, or account verification. Unverified person counts, data fields, and threat-actor claims are not treated as part of the public incident scope. The risk description should rely only on proven fields.\u003C\u002Fp>\n\u003Ch2>Verified Scope and Boundaries\u003C\u002Fh2>\n\u003Cp>For the ShareThis incident, the scope of LeakData should be kept as 40,960,499 unique email accounts. Although the number of account records in external sales lists may exceed approximately 41 million, the main number presented to the user should remain consistent with the number of unique email accounts. The breach date should be tracked as July 9, 2018, and the time of addition to the verified list should be tracked as March 3, 2019. This distinction should be maintained to prevent confusion on the user side between the incident date and the verified addition date.\u003C\u002Fp>\n\u003Cp>Scope; refers to the circulation of ShareThis account data, social sharing tool users, and related account information. This incident should not be presented as a full payment card, bank account, official ID, address book, private message, or browsing history breach. Since some news reports describe a broader wave of data sales, the total number of packages should not be reported as the number of ShareThis users. This distinction both prevents false alarms and provides the user with the correct action list.\u003C\u002Fp>\n\u003Ch2>User Groups at Risk\u003C\u002Fh2>\n\u003Cp>The highest risk is for users who reuse the email and password they use for their ShareThis account on other accounts. If the same credentials are valid for an email account, social media, content management tool, advertising panel, or shopping account, attackers may target these accounts with automated login attempts. Birth date and name information also provide additional material for password reset questions, fake security messages, or phishing messages that appear personal.\u003C\u002Fp>\n\u003Cp>Website owners, content creators, marketing teams, and people who have been using social media tools with the same email address for a long time should also be careful. Even if an old ShareThis account is no longer active, the risk continues if the same email address is used for other work accounts. Accounts opened with corporate email addresses can be connected to attackers' social engineering attempts targeting the company's domain. In accounts opened with personal email addresses, spam, fake membership notifications, and password reset requests are prominent.\u003C\u002Fp>\n\u003Ch2>Urgent Measures to Be Taken\u003C\u002Fh2>\n\u003Cp>A user whose email address is in the ShareThis data should first ensure that the old password used in the ShareThis account is no longer valid for any service today. If the same or a similar password has been used for other accounts, a separate, long, and hard-to-guess password should be set for each account. Using a password manager reduces the risk of reuse. Adding a year, an exclamation mark, or a short suffix to the end of the password is not considered a secure change; the pattern should be completely abandoned.\u003C\u002Fp>\n\u003Cp>Two-factor authentication should be enabled for services including email accounts, social media, content management systems, advertising panels, and payment services. When an unexpected login notification, password reset request, or a link themed around ShareThis or a social sharing tool is received, the sender's address and domain should be checked independently. Old accounts created with the same email address should be reviewed, unused accounts should be closed or isolated with a unique password. If there is any indication of suspicious login, sessions should be terminated and recovery emails should be updated.\u003C\u002Fp>\n\u003Ch2>Long-Term Security Strategies\u003C\u002Fh2>\n\u003Cp>The ShareThis breach shows that old online tool accounts can pose a security risk for a long time. Users should not reuse the same password across work, personal, social media, and marketing tools. Fixed information such as email addresses and birth dates can be used for phishing even years later. Therefore, the inventory of old accounts should be reviewed at regular intervals, memberships that are no longer needed should be closed, and remaining active accounts should be protected with unique passwords.\u003C\u002Fp>\n\u003Cp>The key lesson for service providers is to protect password hashes with modern and costly password storage methods, reduce unnecessary personal data fields, and provide breach notifications quickly. It should be clearly communicated to the user which fields were affected, which fields were not verified, and the date the incident occurred. In the context of ShareThis, since the impact on financial data or official identification has not been verified, risk communication should remain focused on account security, personal data matching, and phishing.\u003C\u002Fp>\n\u003Ch2>Record Control and User Action\u003C\u002Fh2>\n\u003Cp>If the result is positive, the email address, name information, date of birth, and password hash should be considered at risk. If the result is negative, it only means that no match was found in this particular dataset; this does not prove that the person has not been involved in other breaches. An old incident continues to generate current risk if the same password habits persist.\u003C\u002Fp>\n\u003Cp>The correct action is to completely abandon the old password, change all accounts where the same or similar passwords are used, secure the email account with multi-factor protection, and be cautious against fake messages themed around ShareThis or social sharing tools. The user should also check old marketing, social media, publisher, and content tool accounts opened with the same email address. These steps reduce the risk of a 2018 data breach turning into account takeover or targeted phishing today.\u003C\u002Fp>","","ShareThis Data Breach (41 Million Reported Records)","ShareThis Data Breach. 41 Million reported records were reported. Reported data: Dates of birth, Email addresses, Names. Review the scope, risks, and…","\u002Fuploads\u002Flogo\u002Fsharethis_com.webp",false,{"name":7,"sector":35,"country":36,"website":10,"websiteArchiveUrl":29,"websiteStatus":29,"websiteCheckedAt":20},"Social sharing and advertising technology","United States"]