[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f27x6ujdu2so99":3},{"success":4,"breach":5},true,{"_id":6,"name":7,"title":8,"slug":7,"domain":9,"breachDate":10,"addedDate":11,"modifiedDate":11,"contentUpdatedAt":12,"source":13,"sourceUrl":14,"sourceUrls":15,"pwnCount":16,"affectedCount":16,"affectedCountStatus":17,"affectedCountLowerBound":18,"affectedCountUnit":19,"hasEnglishDescription":4,"severity":20,"dataClasses":21,"description":26,"seoTitle":14,"seoTitleEn":27,"seoDescription":14,"seoDescriptionEn":28,"logoUrl":29,"isVerified":4,"isSensitive":4,"isSpamList":30,"isMalware":30,"company":31},"68e3266eda11adda4882542a","xkcd","XKCD Data Breach","xkcd.com","2019-07-01T00:00:00.000Z","2019-09-01T08:58:32.000Z","2026-07-19T00:01:42.163Z","Third party breach","",[],561991,"known",null,"unknown","High",[22,23,24,25],"Email addresses","IP addresses","Passwords","Usernames","\u003Cp>The XKCD data breach is a security incident recorded in July 2019 that affected approximately 562 thousand accounts. In the incident associated with the XKCD webcomic forum, the email, IP, username, and password fields of forum users were exposed. This statement has been prepared to clarify which of the user's data may be at risk and what steps should be taken first.\u003C\u002Fp>\u003Cp>Having the IP address and password field together with the username in forum accounts increases the risk to the account and privacy. The text only uses verifiable data classes; unverified password, payment, identity, or technical claims are not added as data fields. Events with similar names and different years belonging to the same brand are not confused with each other.\u003C\u002Fp>\u003Ch2>Leaked Data Types and Risks\u003C\u002Fh2>\u003Cp>The types of data listed in this incident are as follows: email addresses, IP addresses, passwords, and usernames. The IP address and username can link a technical community account to other online identities. The presence of these fields together may facilitate attackers in preparing fake account reports, fraud, identity correlation, or targeted social engineering attempts.\u003C\u002Fp>\u003Cp>It is understood that the passwords are in MD5 phpBB3 format; therefore, the risk is high for users who reuse the same password. Even if there is no password, the risk is not completely eliminated; address, phone number, date of birth, device information, job profile, loyalty program, web activity, or purchase information can also be sufficient to target the user. If there is a password, it should be urgently checked whether the same password is reused on other services.\u003C\u002Fp>\u003Ch2>Verified Scope and Boundaries\u003C\u002Fh2>\u003Cp>The record covers approximately 562 thousand forum subscribers associated with the domain name xkcd.com. The event is in the verified record category. The scope has been determined by comparing the domain name, company context, country, sector, number of accounts, and data classes. The fields shown to the user are limited to the fields listed in the record.\u003C\u002Fp>\u003Cp>The sector has been corrected to webcomic and forum community rather than retail. In some cases, company verification may be limited, or the dataset may have been distributed in third-party environments. In this case, the explanation focuses on areas that show the user's real risk, without exaggerating the points that are not certain.\u003C\u002Fp>\u003Ch2>User Groups at Risk\u003C\u002Fh2>\u003Cp>XKCD forum users, people who use the same username in technical communities, and accounts with repeated passwords are at risk. The main risk for these users is that leaked domains are matched with common information used on other platforms. If the same email, phone, username, address, social profile, or password is repeated across different accounts, the attack surface increases.\u003C\u002Fp>\u003Cp>The technical forum context can be used in fake private messages, account verification, or community notification messages. Gaming, retail, payment, social profile, travel, investment, airline, and health-wellness contexts produce different risks. The user should consider not only the list of domains but also which account or service those domains are associated with.\u003C\u002Fp>\u003Ch2>Urgent Measures to Be Taken\u003C\u002Fh2>\u003Cp>Affected users should check the password repetition on their forum and email accounts and change accounts where they use the same password. If a password or password-like field has been listed, users should make changes on all accounts where they use the same or similar password, use a unique password, and enable multi-factor authentication wherever possible. The email account should also be protected.\u003C\u002Fp>\u003Cp>If there are fields such as address, phone number, date of birth, device, business profile, purchase or loyalty program, users should check account recovery options, session history, forwarding rules, and suspicious messages. Verification and document requests received in the context of finance, payment, or airlines should be confirmed through a second channel.\u003C\u002Fp>\u003Ch2>Long-Term Security Strategies\u003C\u002Fh2>\u003Cp>Unique passwords, closing old accounts, and secure connection habits that reduce IP visibility are important for forum accounts. In the long term, a password manager, unique passwords, multi-factor authentication, closing old accounts, and deleting unnecessary profile fields are the basic defense. Since permanent personal data cannot be recovered, user behavior and account settings should be strengthened.\u003C\u002Fp>\u003Cp>Data minimization for institutions, the retention period of old customer records, forum and community account permissions, loyalty program fields, and incident reporting processes should be regularly audited. On the user side, not using the same identity information everywhere permanently reduces risk.\u003C\u002Fp>\u003Ch2>Record Control and User Action\u003C\u002Fh2>\u003Cp>If the user matches this record, they should check the XKCD forum account and other forums used with the same username. If a match is seen, the user should read which data fields are listed and determine the order of actions accordingly. If there is a password, changing the password is a priority; if there is an address or phone number, a fraud warning is a priority; if there is finance or payment information, account monitoring is a priority; if there is a social profile, privacy control is a priority.\u003C\u002Fp>\u003Cp>Final assessment: This record is a sensitive forum account incident because it contains an IP address and password. The user should compare this record with their account history; they should individually check the services where they use the same email, phone number, username, address, or password. Any suspicious search, email, message, or account recovery notification should be considered higher risk after the incident.\u003C\u002Fp>","XKCD Data Breach (562 Thousand Reported Records)","XKCD Data Breach. 562 Thousand reported records were reported. Reported data: Email addresses, IP addresses, Passwords. Review the scope, risks, and…","\u002Fuploads\u002Flogo\u002Fxkcd_com.webp",false,{"name":32,"sector":33,"country":34,"website":9,"websiteArchiveUrl":14,"websiteStatus":14,"websiteCheckedAt":18},"XKCD","Webcomic \u002F Forum","United States"]