G
G
Breaches
1
1 verified
Records Exposed
114.0M
Total across all breaches
Data Types Leaked
3
0 high risk
Latest Breach
2020
Gravatar

Breach History

Gravatar
Oct 2020Medium
114M
Records exposed
3
Data types leaked
Verified
Status

In October 2020, a security researcher published a technique for scraping large volumes of data from Gravatar, the service for providing globally unique avatars . 167 million names, usernames and MD5 hashes of email addresses used to reference users' avatars were subsequently scraped and distributed within the hacking community. 114 million of the MD5 hashes were cracked and distributed alongside the source hash, thus disclosing the original email address and accompanying data. Following the impacted email addresses being searchable in HIBP, Gravatar release an FAQ detailing the incident.

Exposed Data Types
Email addressesNamesUsernames
Incident Status
Data breachYes
Data brokerNo
Policy contradictionsNo
Exposed Data Types
Email addressesLow risk
NamesLow risk
UsernamesLow risk