[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f2lrakh5udmn0n":3},{"success":4,"breach":5},true,{"_id":6,"name":7,"title":8,"slug":9,"domain":10,"breachDate":11,"addedDate":12,"modifiedDate":13,"contentUpdatedAt":14,"source":15,"sourceUrl":16,"sourceUrls":17,"pwnCount":18,"affectedCount":18,"affectedCountStatus":19,"affectedCountLowerBound":20,"affectedCountUnit":21,"hasEnglishDescription":4,"severity":22,"dataClasses":23,"description":33,"seoTitle":16,"seoTitleEn":34,"seoDescription":16,"seoDescriptionEn":35,"logoUrl":36,"isVerified":4,"isSensitive":37,"isSpamList":37,"isMalware":37,"company":38},"68e3266eda11adda488253ba","the-grad-cafe","TheGradCafe Data Breach","thegradcafe","thegradcafe.com","2023-02-26T00:00:00.000Z","2023-03-24T04:12:17.000Z","2026-07-03T14:51:06.409Z","2026-07-18T23:59:32.971Z","Third party breach","",[],310975,"known",null,"unknown","High",[24,25,26,27,28,29,30,31,32],"Email addresses","Genders","Geographic locations","IP addresses","Names","Passwords","Phone numbers","Physical addresses","Usernames","\u003Cp>The GradCafe data breach is an incident that occurred in February 2023 on The GradCafe platform, which provides community information about graduate applications and admission processes. The record is associated with 310,975 users. Data classes include email addresses, gender information, geographic locations, IP addresses, names, hashed passwords, phone numbers, physical addresses, and usernames. Due to the educational context, the risk of identification and targeting related to the application process is high.\u003C\u002Fp>\u003Ch2>Leaked Data Types and Risks\u003C\u002Fh2>\u003Cp>When the username, email, name, and location information are combined, the online community identity can be matched with the real person profile. The hashed password field poses a risk for other accounts as well if there are password repetitions. Fields such as IP address and physical address make the user's online behavior and location context more visible.\u003C\u002Fp>\u003Cp>When fields like name, email, phone, or address come together, attackers can approach the user as if there is a legitimate service relationship. This information alone is not proof of account takeover; however, it provides a strong starting point for fake support messages, delivery notifications, password reset attempts, and personalized fraud flows. Since it is related to the registration, training, and application process, fake university communication, admission counseling, application fees, scholarship notifications, or account verification messages may be more convincing. Although it is not expected that every line contains phone numbers and physical addresses, these fields may appear in some records.\u003C\u002Fp>\u003Ch2>Verified Scope and Boundaries\u003C\u002Fh2>\u003Cp>The incident date is February 26, 2023, and the number of affected accounts is recorded as 310,975. Security logs indicate that TheGradCafe personal user data was exposed, passwords were found hashed with bcrypt, and some records may also contain additional fields such as phone number, physical address, and date of birth. The existing data classes are consistent with the main risk areas.\u003C\u002Fp>\u003Cp>It should not be said that passwords are in plain text when explaining the scope. A hashed password still poses a risk if the password is reused. Additionally, this record does not mean that all application results or private messages have been leaked; it should be evaluated through the user account, profile, and communication areas.\u003C\u002Fp>\u003Ch2>User Groups at Risk\u003C\u002Fh2>\u003Cp>Users at risk are those who have created an account on TheGradCafe during the graduate application process, shared their application experience, or appeared with their username in forum-like areas. Those who use the same username on other academic platforms can be matched more easily.\u003C\u002Fp>\u003Cp>Users during the application period may be more open to sensitive themed messages such as scholarships, admission, visas, consulting, or application fees. If geographic location and IP information are combined with the context of the local school or country, targeted messages may appear more realistic.\u003C\u002Fp>\u003Ch2>Urgent Measures to Be Taken\u003C\u002Fh2>\u003Cp>Users in the matched field should change the passwords on their TheGradCafe account and on all accounts where the same password is used. Email accounts, university application portals, and educational platforms where payments are made should be checked first. Two-factor authentication should be enabled wherever possible.\u003C\u002Fp>\u003Cp>Instead of opening incoming links directly, the user should log in through the known web address or application of the relevant service. The fact that the caller knows the name, email, address, or past transaction information does not prove they are trustworthy. One-time verification codes, payment card information, or account passwords should not be shared in any support conversation.\u003C\u002Fp>\u003Ch2>Long-Term Security Strategies\u003C\u002Fh2>\u003Cp>In the long term, a password manager, unique passwords, two-factor authentication on applicable accounts, and the habit of removing unnecessary personal information from accounts reduce risk. Reusing the same email address across different platforms makes it easier to combine different breaches; therefore, using separate email or alias addresses for critical accounts can be considered.\u003C\u002Fp>\u003Cp>Since usernames used in academic communities can be easily matched with real identities, users should reduce unnecessary personal information sharing on forum profiles. Old application accounts should be closed, security questions should be stripped of predictable personal information, and application portals should be protected with separate passwords.\u003C\u002Fp>\u003Ch2>Record Control and User Action\u003C\u002Fh2>\u003Cp>LeakData check shows whether the queried email address is found in this record or not. A positive result does not necessarily mean that all data fields definitively belong to that user; however, it should be considered a sufficient warning for precautionary measures. A negative result only indicates that there is no match in this dataset and does not rule out the possibility of appearing in other breaches.\u003C\u002Fp>\u003Cp>A positive result requires caution, especially for messages related to education applications and account security. A negative result means there is no match within this record; the possibility that the same email address appears on other education platforms should also be checked separately.\u003C\u002Fp>","TheGradCafe Data Breach (311 Thousand Reported Records)","TheGradCafe Data Breach. 311 Thousand reported records were reported. Reported data: Email addresses, Genders, Geographic locations. Review the scope, risks…","\u002Fuploads\u002Flogo\u002Fthegradcafe_com.webp",false,{"name":39,"sector":40,"country":41,"website":10,"websiteArchiveUrl":16,"websiteStatus":16,"websiteCheckedAt":20},"TheGradCafe","Education \u002F Online Community","United States"]