[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fujmr7b7hkdu":3},{"success":4,"breach":5},true,{"_id":6,"name":7,"title":8,"slug":7,"domain":9,"breachDate":10,"addedDate":11,"modifiedDate":12,"contentUpdatedAt":13,"source":14,"sourceUrl":15,"sourceUrls":16,"pwnCount":17,"affectedCount":17,"affectedCountStatus":18,"affectedCountLowerBound":19,"affectedCountUnit":20,"hasEnglishDescription":4,"severity":21,"dataClasses":22,"description":33,"seoTitle":15,"seoTitleEn":34,"seoDescription":15,"seoDescriptionEn":35,"logoUrl":36,"isVerified":4,"isSensitive":4,"isSpamList":37,"isMalware":37,"company":38},"68e3266eda11adda48825382","spoutible","Spoutible Data Breach","spoutible.com","2024-01-31T00:00:00.000Z","2024-02-05T07:33:00.000Z","2026-07-03T15:12:31.942Z","2026-07-18T23:58:20.090Z","Third party breach","",[],207114,"known",null,"unknown","High",[23,24,25,26,27,28,29,30,31,32],"Email addresses","Genders","IP addresses","Names","Passwords","Phone numbers","Usernames","2FA secrets","Backup codes","Password reset tokens","\u003Cp>The Spoutible data breach is a high-risk incident associated with an overly personal information return from a misconfigured service interface on the social media platform Spoutible in January 2024. The record affects 207,114 users. Data classes include email addresses, gender information, IP addresses, names, passwords hashed with bcrypt, phone numbers, usernames, 2FA secret fields, backup codes, and password reset tokens.\u003C\u002Fp>\u003Ch2>Leaking Data Types and Risks\u003C\u002Fh2>\u003Cp>The most critical point in this incident is not just the user profile, but the risk of account takeover. When bcrypt password hashes, 2FA secret and backup code fields, and password reset tokens are found together, attackers may have the opportunity to directly take over some accounts or bypass the second factor.\u003C\u002Fp>\u003Cp>Email, name, username, phone, and IP address make the social media identity more detailed. The record is marked as sensitive; because the 2FA and reset token fields are more critical security materials than ordinary profile information. Users should not be satisfied with just changing the password.\u003C\u002Fp>\u003Ch2>Verified Scope and Boundaries\u003C\u002Fh2>\u003Cp>The incident date is recorded as January 31, 2024, with the number of affected records being 207,114. Reliable technical analyses confirm that the Spoutible service interface returns excessive user data, and fields such as 2FA secret, backup code, and reset token are visible along with password hashes.\u003C\u002Fp>\u003Cp>While explaining the scope, the event should not be limited only to something like an email list. At the same time, it should not be assumed that all users have provided their phone numbers. The correct risk is the simultaneous exposure of profile data and account security materials.\u003C\u002Fp>\u003Ch2>User Groups at Risk\u003C\u002Fh2>\u003Cp>Users at risk are those who have a Spoutible account and use the same phone, 2FA, or password on the platform. Compromise of a social media account can create secondary risks in terms of reputation, private messages, and connected accounts.\u003C\u002Fp>\u003Cp>People who use the same password on other social platforms are at particularly high risk. If 2FA secrets or backup code fields are affected, the second factor needs to be re-established; it should not be assumed that the old codes remain trustworthy.\u003C\u002Fp>\u003Ch2>Urgent Measures to Be Taken\u003C\u002Fh2>\u003Cp>Users in the affected group should change their Spoutible password, log out of all sessions, and re-enable 2FA. Any other accounts using the same password should also be changed. Suspicious sessions should be checked on email accounts and social media accounts.\u003C\u002Fp>\u003Cp>Instead of opening incoming links directly, the user should log in through the known web address or official application of the relevant service. Knowing the caller's name, email, address, order, or profile information does not prove that they are trustworthy. One-time verification codes, payment card information, or account passwords should not be shared in any support conversation.\u003C\u002Fp>\u003Ch2>Long-Term Security Strategies\u003C\u002Fh2>\u003Cp>In the long term, the habit of using a password manager, unique passwords, two-factor authentication, and removing unnecessary personal information from accounts reduces risk. Reusing the same email address across different platforms makes it easier to combine data from different breaches; using a separate email or alias for critical accounts can be considered.\u003C\u002Fp>\u003Cp>2FA secrets and backup codes on social media accounts should be stored in a security vault and recreated after platform-related security incidents. Users can consider stronger methods such as password managers and hardware security keys.\u003C\u002Fp>\u003Ch2>Record Control and User Action\u003C\u002Fh2>\u003Cp>LeakData check indicates whether the queried email address is found in this record. A positive result does not necessarily mean that all data fields definitely belong to that user; however, it is a sufficient warning for precautionary measures. A negative result only indicates that there is no match in this dataset, and does not eliminate the possibility of appearing in other breaches.\u003C\u002Fp>\u003Cp>A positive result requires a high-priority action in terms of account takeover risk. A negative result means there is no match within this record; the same email should be checked separately for other social media violations.\u003C\u002Fp>\u003Cp>The presence of 2FA and reset token fields in this incident requires more careful handling than standard password breaches. The user should not only change their password; they should invalidate old backup codes, set up new two-factor authentication, and close active sessions on the account. Recovery options on other social accounts linked with the same email address should also be checked.\u003C\u002Fp>","Spoutible Data Breach (207.1 Thousand Reported Records)","Spoutible Data Breach. 207.1 Thousand reported records were reported. Reported data: Email addresses, Genders, IP addresses. Review the scope, risks, and…","\u002Fuploads\u002Flogo\u002Fspoutible_com.webp",false,{"name":39,"sector":40,"country":41,"website":9,"websiteArchiveUrl":15,"websiteStatus":15,"websiteCheckedAt":19},"Spoutible","Social Media","United States"]