[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f1bl9jaieyxia3":3},{"success":4,"breach":5},true,{"_id":6,"name":7,"title":8,"slug":7,"domain":9,"breachDate":10,"addedDate":11,"modifiedDate":11,"contentUpdatedAt":12,"source":13,"sourceUrl":14,"sourceUrls":15,"pwnCount":16,"affectedCount":16,"affectedCountStatus":17,"affectedCountLowerBound":18,"affectedCountUnit":19,"hasEnglishDescription":4,"severity":20,"dataClasses":21,"description":27,"seoTitle":14,"seoTitleEn":28,"seoDescription":14,"seoDescriptionEn":29,"logoUrl":30,"isVerified":4,"isSensitive":4,"isSpamList":31,"isMalware":31,"company":32},"68e3266eda11adda488253e1","ubook","Ubook Data Breach","ubook.com","2024-07-28T00:00:00.000Z","2024-07-30T22:25:42.000Z","2026-07-19T00:00:06.816Z","Third party breach","",[],699908,"known",null,"unknown","High",[22,23,24,25,26],"Dates of birth","Email addresses","Genders","Names","Profile photos","\u003Cp>The Ubook data breach is a security incident recorded in July 2024 that affected approximately 700,000 accounts. In this incident related to the audiobook and digital media platform, user profiles, birth dates, and photo links were exposed. This content has been prepared to clearly help users understand which data fields are at risk and which security measures should be prioritized.\u003C\u002Fp>\u003Cp>Fields such as profile photo, gender, and date of birth increase personal profile risk when combined with email and name. Only verifiable data classes have been used in the text; unverified additional claims, different events, or services with similar names have not been merged under this record. This way, the explanation remains both useful to the user and an assessment that is not misleading.\u003C\u002Fp>\u003Ch2>Leaked Data Types and Risks\u003C\u002Fh2>\u003Cp>The types of data listed in this incident are as follows: birth dates, email addresses, genders, names, and profile photos. Profile photos and birth dates can make it easier to match a user with social media or other digital profiles. Linking multiple fields to the same user can make attackers' attempts at fake notifications, account recovery, social engineering, or identity correlation more convincing.\u003C\u002Fp>\u003Cp>In this record, the password field is not listed; this is due to the presence of risk profile and demographic fields together. If there are fields such as password, password hint, private message, official ID, financial information, location, or profile photo, the risk is not limited to email spam risk alone. Even in records without a password, phone, address, IP, date of birth, or social profile information can be used in targeted attacks.\u003C\u002Fp>\u003Ch2>Verified Scope and Boundaries\u003C\u002Fh2>\u003Cp>The record covers approximately 700,000 unique email addresses associated with the domain name ubook.com. The incident is in the verified record class. The scope was written by separately checking the number of accounts, domain name, country, sector, and data classes. Data types not listed are not shown to the user as if they exist.\u003C\u002Fp>\u003Cp>The sector has been corrected to not finance but audiobook and digital media, and the country to Brazil. In some incidents, the company response appears in different contexts such as a third-party service, forum account, newsletter list, or user profile. These records have been separated individually, not duplicated, and the actual service context of the incident has been preserved.\u003C\u002Fp>\u003Ch2>User Groups at Risk\u003C\u002Fh2>\u003Cp>Ubook users, accounts with profile pictures, and people who use the same email address on media or social accounts are at risk. The main risk for these users is that leaked data can be matched with information used on other platforms. If the same email, username, phone number, IP, address, or password is repeated across different accounts, attackers can exploit these common identifiers.\u003C\u002Fp>\u003Cp>The context of media subscriptions can be used in fake subscription renewal, content recommendation, gift membership, or account verification messages. Different contexts such as forums, games, recipes, accommodation, energy, event tickets, newsletters, social media, and finance produce different risks. The user should consider not only the data fields but also which service these fields are associated with.\u003C\u002Fp>\u003Ch2>Urgent Measures to Be Taken\u003C\u002Fh2>\u003Cp>Affected users should check their email security and assess whether their profile pictures match with other accounts. If a password or password hint is listed, users should change it on all accounts where they use the same or similar password, use a unique password, and enable multi-factor authentication wherever possible. Email account security should also be checked.\u003C\u002Fp>\u003Cp>Users should check account recovery options, session history, forwarding rules, and suspicious notifications in records containing phone, address, location, date of birth, private message, social profile, or financial information. Individuals with corporate or publicly accessible profiles should also consider the risk of targeted messages and reputation.\u003C\u002Fp>\u003Ch2>Long-Term Security Strategies\u003C\u002Fh2>\u003Cp>Sharing profile photos and birth dates on digital media accounts should be limited if unnecessary. In the long term, a password manager, unique passwords, multi-factor authentication, closing old accounts, and reducing unnecessary profile information are the basic defenses. Since permanent personal data cannot be changed, user behavior and account settings should be strengthened.\u003C\u002Fp>\u003Cp>For institutions, these events show that backup file accesses, forum account permissions, newsletter subscription data, customer data retention periods, and notification processes need to be regularly audited. For users, not repeating the same identity information across different services and verifying unexpected messages through a second channel provides lasting protection.\u003C\u002Fp>\u003Ch2>Record Control and User Action\u003C\u002Fh2>\u003Cp>If the user matches this record, they should check the use of the same email on media platforms and social accounts. If a match is seen, the user should first read which data fields are listed, then prioritize the steps accordingly. If there is a password, password change should be prioritized; if there is financial data, account monitoring; if there are private messages or social profiles, privacy control; if there is location data, physical security assessment should be prioritized.\u003C\u002Fp>\u003Cp>Final assessment: Although this record does not contain a password, it is a sensitive personal data incident due to the profile photo, date of birth, and gender fields. The user should compare this record with their own account history; services where they have used the same email, phone, username, address, or password should be checked individually. Suspicious search, email, message, or account recovery notifications should be considered higher risk after the incident.\u003C\u002Fp>","Ubook Data Breach (699.9 Thousand Reported Records)","Ubook Data Breach. 699.9 Thousand reported records were reported. Reported data: Dates of birth, Email addresses, Genders. Review the scope, risks, and…","\u002Fuploads\u002Flogo\u002Fubook_com.webp",false,{"name":33,"sector":34,"country":35,"website":9,"websiteArchiveUrl":14,"websiteStatus":14,"websiteCheckedAt":18},"Ubook","Audiobook \u002F Digital Media","Brazil"]