[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f3b72mc0tze4pu":3},{"success":4,"breach":5},true,{"_id":6,"name":7,"title":8,"slug":9,"domain":10,"breachDate":11,"addedDate":12,"modifiedDate":12,"contentUpdatedAt":13,"source":14,"sourceUrl":15,"sourceUrls":16,"pwnCount":17,"affectedCount":17,"affectedCountStatus":18,"affectedCountLowerBound":19,"affectedCountUnit":20,"hasEnglishDescription":4,"severity":21,"dataClasses":22,"description":29,"seoTitle":15,"seoTitleEn":30,"seoDescription":15,"seoDescriptionEn":31,"logoUrl":32,"isVerified":4,"isSensitive":4,"isSpamList":33,"isMalware":33,"company":34},"68e3266eda11adda48825368","ShockGore","ShockGore Data Breach","shockgore","shockgore.com","2020-08-11T00:00:00.000Z","2022-01-20T00:07:47.000Z","2026-07-18T23:57:48.212Z","Verified breach record","",[],73944,"known",null,"unknown","Medium",[23,24,25,26,27,28],"Email addresses","Genders","IP addresses","Passwords","Private messages","Usernames","\u003Cp>The ShockGore data breach is a security incident associated with the exposure of account data belonging to a sensitive website where violent visual content is shared, which occurred in August 2020. According to verified information, the incident took place on August 11, 2020, affecting 73,944 unique email addresses. The dataset includes email addresses, IP addresses, gender information, usernames, private messages, and password data. The password field is linked to unsalted SHA-1 hashes; this poses a serious risk in terms of old password reuse and account takeover attempts.\u003C\u002Fp>\n\u003Cp>The ShockGore record should be handled in a sensitive category. The exposure of the service's subject area and private messages can put users at risk not only in terms of account security but also regarding privacy and reputation. When email addresses, IP addresses, usernames, and private messages are included in the same dataset, attackers may try to match individuals across different platforms, prepare threatening messages, or misuse old conversations. Therefore, the incident requires a clear risk explanation limited to proven data areas.\u003C\u002Fp>\n\u003Ch2>Leaked Data Types and Risks\u003C\u002Fh2>\n\u003Cp>The verified data types are email addresses, gender information, IP addresses, passwords, private messages, and usernames. Email addresses are the primary contact point for targeted phishing messages. Usernames increase the risk of online identity matching if the same nickname is also used in other communities. IP addresses can produce inferences about approximate location, internet service provider, and access habits. Gender information and private messages further increase privacy impact.\u003C\u002Fp>\n\u003Cp>Storing password data with unsalted SHA-1 hashes is a significant technical weakness. Without a salt, the same password produces the same hash value, making it easier for attackers to run trials using ready-made lists. SHA-1 is not a modern password storage standard; short, repeated, or dictionary-based passwords are easier to guess. If the same password has been used on other accounts, the risk can spread to email, social media, gaming, cloud, or financial accounts.\u003C\u002Fp>\n\u003Ch2>Verified Scope and Boundaries\u003C\u002Fh2>\n\u003Cp>Source comparison confirms August 11, 2020 as the date of the ShockGore incident, January 20, 2022 as the addition date, and 73,944 affected email addresses. The verified data fields are email addresses, gender information, IP addresses, passwords, private messages, and usernames. The password context is stated as unsalted SHA-1 hashes. Phone number, physical address, payment card, official identification, real name, date of birth, photo, purchase information, or location history are not among the verified data types for this incident.\u003C\u002Fp>\n\u003Cp>Maintaining this boundary is necessary to provide the user with an accurate picture of the risk. Sensitive classification is related both to the site's subject area and the exposure of private messages. Associating a person with such a service can be misused by third parties. Adding unverified fields produces false alarms; by contrast, email, IP address, username, gender information, private messages, and unsalted SHA-1 password hashes are fields that require direct action.\u003C\u002Fp>\n\u003Ch2>User Groups at Risk\u003C\u002Fh2>\n\u003Cp>The highest risk applies to people who reuse the password they used on their ShockGore account on other services. Even if the old password has been changed, the risk continues if similar password patterns persist across different accounts. People who use the same username on different platforms can be matched more easily. If the email address is associated with personal, work, or family communication, the credibility of targeted messages may increase.\u003C\u002Fp>\n\u003Cp>Users who have private messages are also at risk. Message content, requested material, links, or personal expressions can be used by third parties for the purpose of threatening or embarrassing. A username combined with IP address and gender information may allow the attacker to display the message specifically to the individual. Therefore, the user should check not only their password but also their email account, other accounts associated with the same nickname, and accounts mentioned in private messages.\u003C\u002Fp>\n\u003Ch2>Urgent Measures to Be Taken\u003C\u002Fh2>\n\u003Cp>The first step is to ensure that the old password used on the ShockGore account is not active on any other account. A new, unique, and strong password should be chosen for all services where the same or similar password is used. The email account is a priority because password reset links and security alerts mostly arrive in the email inbox. Two-factor authentication should be enabled on the email account, and recovery addresses and recent sessions should be reviewed.\u003C\u002Fp>\n\u003Cp>The user should be cautious about threats, account warnings, payment requests, or blackmail messages coming from the site name, former username, or private message content. The presence of a real email address, IP region, gender information, or username in the message does not indicate that the message is trustworthy. One should not attempt to log in through the link, attachments should not be opened, and requested information should not be shared. If necessary, all sessions on the relevant accounts should be closed and security notifications should be kept active.\u003C\u002Fp>\n\u003Ch2>Long-Term Security Strategies\u003C\u002Fh2>\n\u003Cp>Using a different password for each service is a basic security rule in the long term. A password manager is an effective solution for finding old repetitions and securely storing strong passwords. If the email address used for accounts belonging to sensitive communities can be separated from daily work and family communication, the risk decreases. Repeating the same username on different platforms for years makes identity matching easier; therefore, the use of a pseudonym should also be included in the security plan.\u003C\u002Fp>\n\u003Cp>Old forum and content community memberships should be reviewed at regular intervals, unnecessary accounts should be closed, and profile information should be reduced. In cases where private messages are leaked, not only the password but also past communications are part of the risk surface. Email archives, old membership notifications, and password reset messages can be used in social engineering attempts. A security plan should include password changes, email protection, multi-factor authentication, and the cleaning up of old accounts together.\u003C\u002Fp>\n\u003Ch2>Record Control and User Action\u003C\u002Fh2>\n\u003Cp>Users who see the result of ShockGore on LeakData should take into account the incident dated August 11, 2020, and the 73,944 affected accounts. Verified fields include email addresses, gender information, IP addresses, usernames, private messages, and passwords. Password data is associated with unsalted SHA-1 hashes. The user's priority is to disable old password repetitions, strengthen their email account, check other accounts using the same nickname, and be cautious against sensitive contextual threat messages.\u003C\u002Fp>\n\u003Cp>In this incident, since the phone number, physical address, payment card, official ID, real name, date of birth, photo, purchase information, and location history have not been verified, the action plan should not be based on this data. In contrast, email, IP address, gender information, username, private messages, and password fields carry real risk. The user should limit the spread of this incident to other accounts by using unique passwords, multi-factor authentication, session history checks, and the habit of not attempting logins through links.\u003C\u002Fp>","ShockGore Data Breach (73.9 Thousand Reported Records)","ShockGore Data Breach. 73.9 Thousand reported records were reported. Reported data: Email addresses, Genders, IP addresses. Review the scope, risks, and…","\u002Fuploads\u002Flogo\u002Fshockgore_com.webp",false,{"name":7,"sector":35,"country":36,"website":10,"websiteArchiveUrl":15,"websiteStatus":15,"websiteCheckedAt":19},"Graphic content forum","Global"]