[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f2klzdexs4mq41":3},{"success":4,"breach":5},true,{"_id":6,"name":7,"title":8,"slug":9,"domain":10,"breachDate":11,"addedDate":12,"publishedAt":13,"modifiedDate":12,"contentUpdatedAt":13,"source":14,"sourceUrl":15,"sourceUrls":16,"pwnCount":19,"affectedCount":19,"affectedCountStatus":20,"affectedCountLowerBound":13,"affectedCountUnit":21,"hasEnglishDescription":4,"contentLocale":22,"availableLocales":23,"translations":25,"severity":28,"dataClasses":29,"description":33,"seoTitle":34,"seoDescription":35,"logoUrl":36,"isVerified":4,"isSensitive":37,"isSpamList":37,"isMalware":37,"company":38},"6aad3518ad803283f053bd80","YS168 2017","YS168 Data Breach","ys168-2017","ys168.com","2017-02-03T00:00:00.000Z","2026-09-18T12:56:56.122Z",null,"YS168 cloud storage network disk user database breach","http:\u002F\u002Fwww.ys168.com\u002F",[15,17,18],"https:\u002F\u002Fsynscan.net\u002F","https:\u002F\u002Fransomlook.io\u002F",276985,"known","unknown","en",[22,24],"tr",{"en":26,"tr":27},{"slug":9},{"slug":9},"High",[30,31,32],"Email addresses","Usernames","Passwords","\u003Cp>\u003Cstrong>The 2017 YS168 (永硕E盘) data breach\u003C\u002Fstrong> occurred in February 2017 when the user database of \u003Cstrong>YS168\u003C\u002Fstrong> (\u003Ccode>ys168.com\u003C\u002Fcode>), a long-running Chinese cloud storage and network disk hosting provider, was leaked online.\u003C\u002Fp>\u003Ch2>What information was affected in the YS168 incident?\u003C\u002Fh2>\u003Cp>The leaked membership dataset (\u003Ccode>ys168.com.txt\u003C\u002Fcode>) contains registered user credentials for cloud storage accounts. The breach compromised records for \u003Cstrong>276,985 unique individuals\u003C\u002Fstrong>, exposing:\u003C\u002Fp>\u003Cul>\u003Cli>\u003Cstrong>Account Identifiers:\u003C\u002Fstrong> Account usernames.\u003C\u002Fli>\u003Cli>\u003Cstrong>Contact Credentials:\u003C\u002Fstrong> Canonical email addresses across major domestic Chinese providers (163.com, 126.com, 21cn.com, qq.com, citiz.net) and international services.\u003C\u002Fli>\u003Cli>\u003Cstrong>Authentication Secrets:\u003C\u002Fstrong> Plaintext account passwords.\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>How many accounts were affected?\u003C\u002Fh2>\u003Cp>Rigorous RFC canonical parsing and deduplication confirmed \u003Cstrong>276,985 unique valid email addresses\u003C\u002Fstrong>.\u003C\u002Fp>\u003Ch2>Technical analysis and security risks\u003C\u002Fh2>\u003Cp>The leak reveals that user credentials were stored completely unhashed in plaintext. Exposure of plain passwords paired directly with email identities poses immediate risks of automated credential-stuffing attacks across webmail and financial accounts.\u003C\u002Fp>\u003Ch2>Recommended actions for affected users\u003C\u002Fh2>\u003Cp>Users who registered with YS168 should:\u003C\u002Fp>\u003Cul>\u003Cli>Immediately update passwords on any email or personal accounts where their storage password was reused.\u003C\u002Fli>\u003Cli>Enable two-factor authentication (2FA) across all vital online services.\u003C\u002Fli>\u003C\u002Ful>","YS168 Data Breach (277 Thousand Reported Records)","YS168 Data Breach. 277 Thousand reported records are reported. Reported data: Email addresses, Usernames, Passwords. Review the scope, risks, and protective…","\u002Fuploads\u002Flogo\u002Fys168.webp",false,{"name":8,"sector":39,"country":40,"website":40,"websiteArchiveUrl":40,"websiteStatus":40,"websiteCheckedAt":13},"Unknown",""]