Breach directory
Wattpad Data Breach (2020)
A storytelling site lost far more than a login table. The Wattpad breach of June 2020 carried names, birth dates, bios and IP addresses next to the password hashes, and within weeks it went from a private sale to a free download.
- Accounts exposed
- 268,765,495
- When it happened
- Jun 2020
- Added to Have I Been Pwned
- Jul 2020
- Data exposed
- Names, usernames, email addresses, IP addresses, genders, dates of birth, geographic locations, bios, social media profiles, user website URLs, passwords
- Passwords stored as
- Mostly bcrypt, salted, with a SHA-256 share, per BleepingComputer
- Wattpad's response
- All passwords reset as a precaution, Jul 2020
Breach data from Have I Been Pwned by Troy Hunt, licensed under CC BY 4.0.
Was your email address in the Wattpad breach?
Enter the address you signed up to Wattpad with. You will see whether it is in the Wattpad record, plus any other breach that holds the same address.
What happened
BleepingComputer started tracking the sale on 7 July 2020, after an anonymous tip about a Wattpad database of over 200 million records being offered privately. A group known for selling stolen company databases was named as the seller, and it denied any part in it when asked.
Sample rows seen by BleepingComputer held usernames, real names, hashed passwords, email addresses and a rough location, and one person in the sample confirmed their details were accurate. Wattpad said it had brought in outside security consultants. In an updated statement published by BleepingComputer on 14 July 2020, the company added that no payment details or stories had been touched and that active users’ passwords were salted and hashed.
On the day BleepingComputer published, the set went free. Someone registered on a hacking forum under a stolen reporter’s identity and posted the Wattpad set for free, claiming 271 million users, well above the user count Wattpad had been reported to have. Have I Been Pwned added 268,765,495 unique email addresses from the Wattpad data breach later in July 2020.
In June 2020, the user-generated stories website Wattpad suffered a huge data breach that exposed almost 270 million records. The data was initially sold then published on a public hacking forum where it was broadly shared.
What was exposed
Eleven kinds of data sit in the Wattpad record: email addresses, usernames, names, genders, dates of birth, IP addresses, geographic locations, bios, social media profiles, user website URLs and password hashes.
Alone, each field in the Wattpad breach is minor. Together they describe a person: what they are called, roughly where they live, how old they are, the network they wrote from, and the profile text and linked accounts they chose to share. Usernames and social media profiles connect a Wattpad identity to accounts elsewhere, so a stranger holding one row can often find the rest of someone’s online life.
How the passwords were stored
Have I Been Pwned records the Wattpad passwords as bcrypt hashes, and Wattpad said they were salted. Whoever gave the set away claimed something less tidy: 145 million bcrypt hashes and 44 million made with SHA-256. BleepingComputer saw that same mix in its samples.
bcrypt is built to be slow, so each guess costs real time and every salted hash has to be attacked on its own. SHA-256 is fast, which makes it a poor choice for passwords even with a salt: weak and common ones on that portion fall quickly. You cannot tell which kind your account had, so plan for the worse case.
Timeline
Jun 2020
Wattpad data taken, per Have I Been Pwned.
Jul 2020
BleepingComputer begins tracking a private sale on 7 July 2020; the price quoted is ten bitcoins.
Jul 2020
Wattpad tells BleepingComputer on 14 July 2020 it is containing the incident with outside consultants.
Jul 2020
Posted for free on a hacking forum, the set spreads widely.
Jul 2020
Per BleepingComputer's 20 July 2020 update, Wattpad resets every user password out of precaution.
Disclosure lag
A few weeks. Users heard through the press first, then got a forced reset.
What to do now
Your Wattpad password was reset for you, so the risk now lives wherever else you used it. Change that password on every site that shares it, starting with email, and turn on two-factor sign-in there. A birth date cannot be changed, so the rest is about attention.
Expect messages that know your name, your city and your birthday, and treat that familiarity as a warning sign, not proof. If your bio or linked social media profiles reveal more than you want tied to this email address, trim them. Run the free LeakNix check to see the other breaches that carry the same address.
Questions about the Wattpad breach
When was the Wattpad breach?
- Have I Been Pwned dates it to June 2020. It became public in July 2020, when BleepingComputer reported a private sale and the data was then posted free on a hacking forum.
Were Wattpad passwords exposed?
- Yes, as hashes. Most were bcrypt, which resists cracking, but the person who published the set claimed about 44 million used SHA-256, which is much faster to attack. Wattpad reset every password in July 2020.
What personal details did the Wattpad data breach include?
- Names, usernames, email addresses, genders, dates of birth, IP addresses, locations, bios, linked social media profiles and website URLs, alongside the password hashes.
Related breaches
The Wattpad data breach record here (268,765,495 accounts, Jun 2020) is from Have I Been Pwned under CC BY 4.0, with no endorsement of LeakNix implied.
LeakNix