15 July 2020

Account data of 271 million Wattpad users is available for free on a hacker forum


Account data of 271 million Wattpad users is available for free on a hacker forum

A database allegedly containing stolen data of 271 million Wattpad users, which was previously being sold for 10 bitcoins (nearly $100,000), is now being offered for free on hacker forums.

Wattpad is a popular free online storytelling community where users post written works such as articles, stories, fan fiction, and poems.

According to Bleeping Computer, which has been tracking the alleged private sale of a Wattpad database containing over 200 million records since the beginning of July, the rumors emerged that the database was put for sale by Shiny Hunters, a group notorious for selling company databases obtained in data breaches. However, Shiny Hunters told Bleeping Computer that they have nothing to do with this database.

BleepingComputer examined a few sample records of this database and found it contained user names, names, hashed passwords, email addresses, and general geographic location.

Kiel Hume, Director of PR & Communications at Wattpad, confirmed in a statement that the company is investigating the potential breach, but “no financial information, stories, private messages, or phone numbers were accessed during this incident.”

The alleged database is being offered for free on the hacker forum by a user impersonating a known cyber security reporter, “who claims to be revealing the identity of Shiny Hunters and other data breach sellers this week.”

According to the user, 145 million passwords included in the database are hashed with bcrypt, while 44 million are hashed with SHA256.

“The number of users reported to be in this stolen database conflicts with the reported 80 million total users on Wattpad in 2019,” Bleeping Computer pointed out.

Back to the list

Latest Posts

Threat actors increasingly abusing Microsoft Graph

Threat actors increasingly abusing Microsoft Graph

Graph API is often used for discreet communications to cloud-based C&C servers.
6 May 2024
Marriott admits its systems were not encrypted before 2018 data breach

Marriott admits its systems were not encrypted before 2018 data breach

Marriott has acknowledged that it used SHA-1 algorithm, which does not qualify as encryption.
6 May 2024
Russian military spies APT28 exploited Outlook 0day to attack Czechia and Germany

Russian military spies APT28 exploited Outlook 0day to attack Czechia and Germany

The attacks targeted entities "related to Russia's war of aggression against Ukraine."
6 May 2024