[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f3ni3q4huugcs2":3},{"success":4,"breach":5},true,{"_id":6,"name":7,"title":8,"slug":9,"domain":10,"breachDate":11,"addedDate":12,"modifiedDate":12,"contentUpdatedAt":13,"source":14,"sourceUrl":15,"sourceUrls":16,"pwnCount":17,"affectedCount":17,"affectedCountStatus":18,"affectedCountLowerBound":19,"affectedCountUnit":20,"hasEnglishDescription":4,"severity":21,"dataClasses":22,"description":30,"seoTitle":15,"seoTitleEn":31,"seoDescription":15,"seoDescriptionEn":32,"logoUrl":33,"isVerified":4,"isSensitive":4,"isSpamList":34,"isMalware":34,"company":35},"68e3266eda11adda4882539f","survey-lama","SurveyLama Data Breach","surveylama","surveylama.com","2024-02-01T00:00:00.000Z","2024-04-02T23:04:58.000Z","2026-07-18T23:58:48.400Z","Third party breach","",[],4426879,"known",null,"unknown","Critical",[23,24,25,26,27,28,29],"Dates of birth","Email addresses","IP addresses","Names","Passwords","Phone numbers","Physical addresses","\u003Cp>The SurveyLama data breach is a security incident recorded in February 2024 that affected approximately 4.43 million accounts. In the incident related to the paid survey and reward platform, user identity, contact information, address, IP, and password fields were exposed. This content has been prepared so that users can understand the scope of the incident, the leaked fields, the risk level, and the steps they need to take, all on a single page.\u003C\u002Fp>\u003Cp>Since survey platforms are related to users' demographic profiles and reward account behaviors, the contact and password fields can be used more selectively. Only data classes that can be verified are included in the description; different services with the same name, additional claims whose technical details are unclear, or information whose scope is not proven are not presented as a data field. This approach makes the real risk visible without misleading the user.\u003C\u002Fp>\u003Ch2>Leaking Data Types and Risks\u003C\u002Fh2>\u003Cp>The types of data listed in this incident are: birth dates, email addresses, IP addresses, names, passwords, phone numbers, and physical addresses. Address, phone, date of birth, and IP information increase account and identity risk when combined with email and password fields. When these fields are used together, they can lead to outcomes such as account takeover, social engineering, fraud, physical targeting, or privacy violations.\u003C\u002Fp>\u003Cp>It appears that passwords are stored using different hashing methods such as salted SHA-1, bcrypt, or argon2; nevertheless, users with repeated passwords are at risk. One of the most critical risks in records containing passwords is using the same or similar password on other services. In records without passwords, fields such as device, location, phone, address, education, job application, or financial context can make targeted messages more convincing.\u003C\u002Fp>\u003Ch2>Verified Scope and Boundaries\u003C\u002Fh2>\u003Cp>The record covers approximately 4.43 million user accounts associated with the domain surveylama.com. The incident is classified as a verified record. In the scope assessment, the number of accounts, domain, sector, country, and data classes were checked separately. The data fields shown to the user were limited to those actually listed within the record.\u003C\u002Fp>\u003Cp>The sector has been corrected to a paid survey and reward platform, not retail. This limit is particularly important for similar brand names, records covering multiple services, or sensitive sectors. The record has not been merged with another event, expanded in a way that would create duplicate records, and the company context has been clarified as much as possible.\u003C\u002Fp>\u003Ch2>User Groups at Risk\u003C\u002Fh2>\u003Cp>SurveyLama users, people who have a reward account, and those who use the same password on other survey or shopping sites are at risk. The main risk for these people is that the leaked fields are matched with common information used in other accounts. When the same email address, phone number, username, device ID, or password is repeated, attackers can try this information on different services.\u003C\u002Fp>\u003Cp>The context of rewards and surveys can be used in fake payment, point withdrawal, survey invitation, or profile completion messages. For corporate users, work email and job information stand out, while for individual users, address, date of birth, purchases, location, or membership context is prominent. In fields such as education, telecommunications, finance, travel, politics, job applications, and VPNs, the context itself can also increase targeting risk.\u003C\u002Fp>\u003Ch2>Urgent Measures to Be Taken\u003C\u002Fh2>\u003Cp>Affected users should change their passwords and check their reward accounts and payment redirects. If a password or password-like field is listed, users should change it on all accounts where they use the same password, use a unique password, and enable multi-factor authentication where possible. Operating on only a single platform may not be sufficient.\u003C\u002Fp>\u003Cp>If there are fields such as phone, address, date of birth, device ID, official ID, job application, or reward balance, users should check account recovery information, registered sessions, email forwarding, and suspicious messages. For institutions, processes should be updated against employee alerts, fake invoices, and account verification attempts.\u003C\u002Fp>\u003Ch2>Long-Term Security Strategies\u003C\u002Fh2>\u003Cp>Personal profile fields on reward platforms should be limited as much as possible, and unique passwords should be used for survey accounts. In the long term, a password manager, unique passwords, multi-factor authentication, closing old accounts, deleting unnecessary profile fields, and data minimization form the basic security line. Since permanent personal data cannot be recovered, defense relies on strengthening account behavior.\u003C\u002Fp>\u003Cp>On the company and institutional side, post-incident inventory, access permissions, storage of old data, notification processes, and the use of third-party platforms should be reconsidered. On the user side, avoiding the repetition of the same identity information across different services and the habit of verifying suspicious communications through a second channel provide lasting protection.\u003C\u002Fp>\u003Ch2>Record Control and User Action\u003C\u002Fh2>\u003Cp>If the user matches with this record, they should check all the reward platforms they use with the same email and password alongside SurveyLama. If a match is seen, the user should first read which data fields are listed, and then prioritize the steps according to these fields. If there is a password, password change should be prioritized; if there is an official ID, ID monitoring; if there is location or device information, device security; if there is education or job application, institution account check should be prioritized.\u003C\u002Fp>\u003Cp>Final assessment: This record is a sensitive customer data incident due to the password, address, phone number, date of birth, and IP fields. The user should compare this record with their account history; they should separately check the services where they use the same email, phone number, username, or password. Unexpected calls, messages, emails, or account recovery notifications should be considered higher risk after the incident.\u003C\u002Fp>","SurveyLama Data Breach (4.4 Million Reported Records)","SurveyLama Data Breach. 4.4 Million reported records were reported. Reported data: Dates of birth, Email addresses, IP addresses. Review the scope, risks, and…","\u002Fuploads\u002Flogo\u002Fsurveylama_com.webp",false,{"name":36,"sector":37,"country":38,"website":10,"websiteArchiveUrl":15,"websiteStatus":15,"websiteCheckedAt":19},"SurveyLama","Paid Survey \u002F Rewards Platform","France"]