Data breach
000webhost
- Records
- 15,249,573
- Breach date
- 1 March 2015Estimated
- Added
- 1 December 2024
What was exposed
3 types of data · 2 more reported · 1 puts you at serious risk
- Email addresses15,249,573
- Passwords15,249,534
- IP addresses15,130,801
- UsernamesReported, not counted
- NamesReported, not counted
Reported in the breach write-up; not counted in the analysed data.
About this breach
In 2015, the free web hosting provider 000webhost lost a database containing more than 15 million customer records to attackers who exploited an old version of PHP on the company's website. The stolen data circulated on underground markets for months before the company publicly acknowledged the incident, and the passwords in the database were stored in unencrypted, readable form. According to our investigation team, the listing contains 15,249,573 records, with email addresses and passwords present in nearly all of them and IP addresses in more than 15.1 million. Our team estimates the attack occurred around March 1, 2015, based on the indexed data.
Breach Timeline
October 27, 2015: 000webhost says it became aware of the breach on its main server and began troubleshooting the same day, according to the company's own notice.
October 28, 2015: Forbes reported that usernames and plaintext passwords for more than 13.5 million users appeared to have leaked from the free web host, after a source provided a copy of the database for verification.
October 29, 2015: 000webhost publicly acknowledged the breach on its Facebook page, blaming an exploit in an old PHP version, as reported by ComputerWeekly.
What Information Was Compromised?
Our analysis found the following data types in this breach: email addresses, passwords, and IP addresses, in the counts shown above.
The company's own notice, published after the breach was discovered, said the stolen data also included usernames and names. Multiple outlets, including Sophos and Acunetix, reported that the passwords were stored in plaintext, meaning they were not hashed or encrypted and could be read directly by anyone with the database.
Not every individual is affected by every type of data listed here.
What Are the Potential Risks for Affected Individuals?
Because passwords were stored in readable form, anyone holding this database can log into affected 000webhost accounts directly. Since many people reuse the same password across sites, the same credentials may also work on email, banking, and social media accounts.
The email addresses paired with real passwords are valuable for phishing. Attackers can send convincing messages that appear to come from legitimate services, referencing real account details to pressure recipients into clicking malicious links or handing over more information. The inclusion of IP addresses adds another layer of exposure, revealing roughly where each user was when they signed up.
The company itself acknowledged in its notice that FTP passwords had been stolen as well, which could give attackers access to the files hosted on affected customers' websites.
What Is 000webhost Doing in Response?
In its October 29, 2015 notice, signed by CEO Arnas Stuopelis, the company said it removed illegally uploaded files, temporarily blocked access to its website, members area, and FTP services, reset all user passwords to random values, and increased its level of encryption. It said it was working around the clock to identify and eliminate security flaws, updating and patching its systems, and would cooperate with law enforcement. The company advised customers to reset their passwords when the service came back online, avoid reusing old passwords, change passwords shared with other services, and consider two-factor authentication.
What Should You Do If You Were Affected?
If you had an account with 000webhost around 2015, take these steps:
Change your 000webhost password. The company reset all passwords, but you should set a strong, unique one when you regain access.
Change the password anywhere else you reused it. This is the most important step. Attackers try leaked credentials against email, banking, and shopping sites first.
Watch for phishing. Treat unexpected emails about your hosting account or other services with suspicion, and do not click links in them.
Turn on two-factor authentication where services offer it, especially for email, which often controls password resets for everything else.
Check your accounts for unusual activity, including unfamiliar logins or password reset notices you did not request.
In the news
- Forbes: 13 Million Passwords Appear To Have Leaked From This Free Web Hostforbes.com (opens in a new tab)
- Sophos: Webhosting company loses 13m plaintext passwordsnews.sophos.com (opens in a new tab)
- ComputerWeekly: 000Webhost blames PHP exploit for breach of 13.5 million recordscomputerweekly.com (opens in a new tab)
- Acunetix: 000webhost Breach Exposes 13 Million Passwordsacunetix.com (opens in a new tab)
- Mozilla Monitor: 000webhost Data Breachmonitor.mozilla.org
