Data breach
Animoto
- Records
- 25,400,868
- Breach date
- 10 July 2018Estimated
- Added
- 1 December 2024
What was exposed
3 types of data · 2 more reported · 1 puts you at serious risk
- Email addresses25,398,692
- Names21,399,322
- Passwords16,701,634
- GenderReported, not counted
- Dates of birthReported, not counted
Reported in the breach write-up; not counted in the analysed data.
About this breach
On July 10, 2018, the video creation platform Animoto detected unusual activity on its systems. The company later confirmed the activity was unauthorized and that user data may have been obtained. The breach is associated with about 25.4 million records, including more than 25.3 million email addresses, roughly 21.4 million names, and about 16.7 million passwords. No individual or group has publicly claimed responsibility for the incident.
July 10, 2018: Animoto received an alert of unusual activity on its system. The company says data was accessed on this date, according to its security announcement.
August 6, 2018: Animoto confirmed the activity was unauthorized and that user data may have been obtained, per the company's announcement.
August 16, 2018: Animoto began notifying users about the incident, according to the company's security announcement.
August 20, 2018: TechCrunch reported the breach after Animoto filed notice with the California attorney general.
What Information Was Compromised?
Our analysis found the following data types in this breach: passwords, email addresses, and names.
Animoto's own security announcement listed additional details that may have been accessed: first name, last name, username (email address), hashed and salted passwords, geolocation, gender, and date of birth.
Not every individual is affected by every type of data listed here.
The passwords were stored hashed and salted, a technique that makes it harder to recover the original text, but Animoto said it was unclear whether the key used to secure them was also accessed. The company stated that complete payment card data was kept in a separate system and was not accessed. Animoto also noted at the time that it did not keep geolocation information for all users.
What Are the Potential Risks for Affected Individuals?
Even hashed and salted passwords can sometimes be cracked, particularly if they were weak or reused elsewhere. Anyone who used the same password on Animoto and other accounts, such as email, banking, or social media, may face credential stuffing, where attackers try leaked email and password pairs on other services.
The combination of names, email addresses, dates of birth, and gender can also support targeted phishing. Messages that reference a person's real name or account details are more convincing and can trick recipients into handing over further information or login credentials.
Animoto said at the time it had no evidence of actual or attempted fraudulent misuse of the information. That does not eliminate the risk of misuse years later, because leaked credentials remain useful to criminals long after a breach.
What Is Animoto Doing in Response?
Animoto notified users beginning August 16, 2018, and filed reports with state authorities, including the California attorney general, according to TechCrunch. The company advised all users to change their Animoto passwords as an immediate precaution.
In its security announcement, Animoto said it worked with outside forensic experts, notified law enforcement, and continued to monitor for suspicious activity. The company also said it reset employee passwords, reduced employee access to critical systems, and was rebuilding parts of its infrastructure to improve security.
What Should You Do If You Were Affected?
Change your Animoto password immediately, especially if you have not done so since 2018.
If you used the same or a similar password on any other account, change those passwords too. Email accounts should be prioritized, since they are often the recovery path for other services.
Turn on two-factor authentication where it is offered, starting with your email provider.
Watch for phishing emails that appear to come from Animoto or other services, and do not click links in unexpected messages about account problems.
