Data breach
123RF
- Records
- 8,602,433
- Breach date
- 22 March 2020Estimated
- Added
- 1 December 2024
What was exposed
7 types of data · 1 puts you at serious risk
- Email addresses8,591,233
- IP addresses8,219,868
- Passwords7,917,781
- Names7,349,448
- Phone numbers2,322,572
- Home addresses1,659,735
- Facebook profiles1,628,728
About this breach
123RF, a popular royalty-free stock photo service, suffered a data breach in which a database containing millions of customer records was copied from a server operated by its parent company, Inmagine Group. According to our investigation team, the incident is estimated to have occurred on March 22, 2020, and the listing covers 8,602,433 rows of member data. Reporting by BleepingComputer and CyberNews found that the database appeared for sale and later as a free download on hacker forums in November 2020. Inmagine Group confirmed to those outlets that a server at its data center was breached and that the intruder "proceeded to copy the membership data." The company said the sold database was likely an older version rather than the current 2020 dataset, and that no financial information was stored in it.
Breach Timeline
March 22, 2020: According to CyberNews and Hackread, the most recent data in the leaked database appears to have been copied from 123RF's data center on this date.
November 2020: BleepingComputer reported that a known data breach broker began selling a database of 8.3 million 123RF user records on a hacker forum.
November 8, 2020: Hackread reported that the database was leaked for download on a hacker forum, and attributed the breach to the hacker known as ShinyHunters. BleepingComputer's reporting did not confirm the actor's identity.
What Information Was Compromised?
Our analysis found the following data types in this breach: email addresses (8,591,233), IP addresses (8,219,868), passwords (7,917,781), names (7,349,448), phone numbers (2,322,572), home addresses (1,659,735), and Facebook account identifiers (1,628,728).
BleepingComputer and CyberNews reported that the passwords were stored as MD5 hashes, a weak method, and that BleepingComputer was able to recover plain-text passwords for numerous accounts using online cracking tools. The leaked file also included PayPal email addresses for some users, according to CyberNews.
Not every individual is affected by every type of data listed here.
What Are the Potential Risks for Affected Individuals?
Because many of the passwords were weakly hashed and could be recovered in plain text, the most direct risk is credential stuffing, where criminals try stolen email and password combinations on other websites to break into accounts. People who reused their 123RF password elsewhere are especially exposed.
The names, addresses, and phone numbers in the database can be used for targeted phishing, scam calls, or identity fraud. The inclusion of PayPal email addresses and Facebook identifiers may enable convincing social engineering attempts. CyberNews also noted that exposed IP addresses could be scanned for vulnerable devices.
What Is 123RF Doing in Response?
In statements reported by BleepingComputer and CyberNews in November 2020, Inmagine Group said it was notifying affected members and the relevant authorities, and working with law enforcement. The company also said it was tightening security policies to require stronger passwords and use IP detection to flag suspicious log-ins. A company representative said it could not conclusively confirm that the sample shared by the threat actor covered the full number of records, and said the database was likely about a year old.
What Should You Do If You Were Affected?
Change your 123RF password immediately, and change it anywhere else you reused it.
Enable two-factor authentication on your email, PayPal, Facebook, and other important accounts.
Watch for phishing emails that reference 123RF, your photo purchases, or billing, and do not click unexpected links.
Be cautious with unexpected calls or messages that use your name, address, or phone number.
Consider using a password manager to create unique passwords for every account.
In the news
- BleepingComputer: Popular stock photo service hit by data breach, 8.3M records for salebleepingcomputer.com (opens in a new tab)
- CyberNews: 8.5+ million user records from royalty-free image website leaked on Russian hacker forumcybernews.com (opens in a new tab)
- Hackread: Image stock site 123RF hacked; 8.3M user database leakedhackread.com (opens in a new tab)
- ITPro: Hackers steal 8.3 million user records from 123RFitpro.com (opens in a new tab)
