[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f39ajpcy4mtsu":3},{"success":4,"breach":5},true,{"_id":6,"name":7,"title":8,"slug":9,"domain":10,"breachDate":11,"addedDate":12,"modifiedDate":12,"contentUpdatedAt":13,"source":14,"sourceUrl":15,"sourceUrls":16,"pwnCount":22,"affectedCount":22,"affectedCountStatus":23,"affectedCountLowerBound":24,"affectedCountUnit":25,"hasEnglishDescription":4,"severity":26,"dataClasses":27,"description":35,"seoTitle":36,"seoTitleEn":37,"seoDescription":36,"seoDescriptionEn":38,"logoUrl":39,"isVerified":4,"isSensitive":40,"isSpamList":40,"isMalware":40,"company":41},"68e3266eda11adda48825422","Yam","Yam Data Breach","yam","yam.com","2013-06-02T00:00:00.000Z","2021-05-22T08:02:31.000Z","2026-07-20T09:14:42.776Z","Database leak","https:\u002F\u002Ftwitter.com\u002FStillAzureH\u002Fstatus\u002F1383234219153846276",[15,17,18,19,20,21],"https:\u002F\u002Fwww.ithome.com.tw\u002Fnews\u002F144589","https:\u002F\u002Fwww.ntrc.edu.tw\u002Fannounce\u002Fan20210603-2.html","https:\u002F\u002Fwww.yam.com\u002F","https:\u002F\u002Fdatabreach.com\u002Fbreach\u002Fyam-2013","https:\u002F\u002Fdehashed.com\u002Finsights\u002Fyam-com-data-breach-2013-june",13258797,"known",null,"unknown","Critical",[28,29,30,31,32,33,34],"Dates of birth","Email addresses","Names","Passwords","Phone numbers","Physical addresses","Usernames","\u003Cp>The \u003Cstrong>Yam data breach\u003C\u002Fstrong> is a verified incident dated 2 June 2013 involving 13,258,797 unique email addresses.\u003C\u002Fp>\u003Ch2>Types of Exposed Data and Risks\u003C\u002Fh2>\u003Cp>The verified corpus contained dates of birth, email addresses, names, usernames, phone numbers, physical addresses and \u003Cstrong>unsalted MD5 password hashes\u003C\u002Fstrong>. There is no evidence that plaintext passwords were published, but unsalted MD5 is a fast and weak hashing method by modern standards. The figure of 13,258,797 measures unique email addresses. Some secondary lists state approximately 16 million records, but that total is not a clearly defined unique-account measure and is not used here.\u003C\u002Fp>\u003Ch2>Breach Timeline and Technical Details\u003C\u002Fh2>\u003Cp>The incident relates to user data from the Taiwan-based web portal Yam.com dated June 2013. The corpus was examined and verified after appearing on a popular hacking forum years later, in 2021, and was added to public breach catalogues on 22 May 2021. Yam is a longstanding Taiwanese portal that has offered search, news, email, blog, video and community services, so the record should not be assigned to a United States company with a similar name or described only as a social-media application. The initial access method, exploited weakness and server or backup from which the information was taken have not been disclosed. Classification as a database leak describes the publication of the user database on a forum; it does not assert a particular technical attack vector. The eight-year gap between incident and catalogue dates does not mean that the breach occurred in 2021.\u003C\u002Fp>\u003Ch2>User Groups at Risk\u003C\u002Fh2>\u003Cp>The greatest risk applies to people who opened an account for Yam’s portal, email, blog or community services around 2013 and reused the same password elsewhere. Someone who forgot the old account or no longer uses the service may remain exposed because an email address, birth date, phone number and physical address do not automatically change. Unsalted MD5 hashes create a higher offline-cracking risk, especially for short and common passwords. If the same password protected the email account, attackers may obtain password-reset links for other services. Address and birth-date information can help criminals answer weak verification questions used by a bank or telecom provider. People whose phone numbers appear in the data should be cautious of fake support, delivery and account-security calls. A match does not mean that payment cards, bank accounts or government identity numbers were exposed; those fields are not among the verified data classes.\u003C\u002Fp>\u003Ch2>Immediate Steps to Take\u003C\u002Fh2>\u003Cp>If you remember the password used for Yam around 2013, identify every account that still uses the same or a similar password. Starting with email, banking, telecom and social accounts, create a long \u003Cstrong>unique password\u003C\u002Fstrong> for every service; a trusted password manager reduces reuse. Enable app-based or security-key two-step verification wherever available and close active sessions you do not recognise. Review the recovery phone, backup address, forwarding rules and connected applications on the email account. Do not trust someone claiming to represent Yam or another institution merely because they know an old address, birth date or phone number while requesting a password, one-time code or payment. Type the institution’s known address yourself instead of following a message link. If failed sign-in, unexpected password reset or new-device alerts appear, change the relevant password immediately and inspect session history. Preserve the date, number and sender details of suspicious calls and messages.\u003C\u002Fp>\u003Ch2>Long-Term Security Strategies\u003C\u002Fh2>\u003Cp>A birth date and historical address cannot be rotated as easily as a password, so protection should continue beyond the first weeks. Use password-manager security reports to replace reused, weak or previously exposed passwords regularly. Treat the email account as the centre of digital identity and protect it with a strong password, two-step verification and current recovery options. Avoid truthful answers to security questions based on a birthplace, school or family name; where a service allows it, create random answers. If one username is reused on many platforms, remember that attackers can connect those accounts and make phishing more convincing. Treat messages containing an old phone number or address with caution, since criminals may use outdated data to prove a supposed past relationship. Before closing an unused account, remove profile fields, connected applications and active sessions. When another Yam dataset appears, compare its date, fields and unique-account count to decide whether it is a new incident or another copy of the 2013 data.\u003C\u002Fp>\u003Ch2>Check Your Data\u003C\u002Fh2>\u003Cp>Search LeakData.io with the email address used for Yam around 2013 to see whether it matches this record. A match shows that the address is present in the verified corpus; it does not mean all seven listed data types were complete in the individual record. An empty result does not prove that no account created with another address exists, so check old personal and work addresses separately. Never provide a password, password hash, one-time code, payment information or identity document in response to a search result. If a match appears, remove old password reuse first, secure the email account and enable two-step verification. When reviewing new Yam breach figures, do not compare the established 13,258,797 unique-email count with total rows or an undefined claim of approximately 16 million as though they were the same measure. Keeping the June 2013 incident separate from the 2021 forum publication also preserves the correct risk timeline.\u003C\u002Fp>","","Yam Data Breach (13.3 Million Reported Records)","Yam Data Breach. 13.3 Million reported records were reported. Reported data: Dates of birth, Email addresses, Names. Review the scope, risks, and protective…","\u002Fuploads\u002Flogo\u002Fyam_com.webp",false,{"name":7,"sector":42,"country":43,"website":10,"websiteArchiveUrl":36,"websiteStatus":36,"websiteCheckedAt":24},"Technology","Taiwan"]