Data breach
Appen
- Records
- 5,887,998
- Breach date
- 22 June 2020Estimated
- Added
- 1 December 2024
What was exposed
5 types of data · 1 puts you at serious risk
- Names5,887,730
- Email addresses5,886,083
- IP addresses32,092
- Phone numbers12,734
- Passwords5,087
About this breach
In 2020, the data of roughly 5.9 million people tied to Appen, an Australian company that runs crowdsourced data-labeling and online micro-work platforms, leaked online. According to our investigation team, the breach occurred around June 22, 2020, and the records surfaced publicly weeks later as part of one of the largest coordinated data dumps of the year. Appen, which acquired the crowdsourcing firms Figure Eight (formerly CrowdFlower) and Leapforce in 2019, was one of 18 companies whose databases appeared in the dump, alongside services such as Wattpad, Dave.com, and Drizly.
Breach Timeline
July 21, 2020: A threat actor known as ShinyHunters began posting the stolen databases for free on a hacker forum used for selling and sharing stolen data, according to BleepingComputer.
July 28, 2020: BleepingComputer reported that the combined dump of 18 databases exposed more than 386 million user records, listing Appen at roughly 5.8 million records. The outlet noted that Appen's breach had not been previously disclosed, and that the company did not respond to requests for comment.
What Information Was Compromised?
Our analysis found the following data types in this breach: names, email addresses, passwords, phone numbers, and IP addresses. Our investigation team indexed close to 5.9 million rows, including about 5.9 million email addresses and names, more than 5,000 passwords, roughly 12,700 phone numbers, and about 32,000 IP addresses.
Not every individual is affected by every type of data listed here.
Commenters on the BleepingComputer report noted that many of the exposed email addresses were tied to accounts on Figure Eight and CrowdFlower, platforms Appen had acquired, rather than the main Appen site itself. The records listed in this breach were part of ShinyHunters' free dump; according to BleepingComputer, the actor said the databases had been sold privately first before being released publicly.
What Are the Potential Risks for Affected Individuals?
The most immediate risk involves passwords. Where password fields were included in the dump, criminals can try those credentials against other websites, a technique known as credential stuffing. If you reused the same password across accounts, a single leaked password can unlock email, banking, or social media logins.
Names, email addresses, and phone numbers also fuel targeted phishing. Scammers can use real names and breached account details to craft convincing messages that appear legitimate, such as fake security alerts or payment notifications. IP addresses add location context that makes such messages more believable. Because the full database circulated freely on a public forum, anyone can download and search it indefinitely.
What Should You Do If You Were Affected?
Change your password. If you had an account with Appen, Figure Eight, CrowdFlower, or Leapforce, set a new, unique password there immediately.
Check other accounts. If you used the same or a similar password anywhere else, change those passwords too. A password manager can help you create and track unique credentials.
Watch for phishing. Be cautious with emails or texts referencing your account, and avoid clicking links or entering credentials through emailed links. Go to the site directly instead.
Turn on two-factor authentication where services offer it, especially for your primary email account.
Monitor your accounts. Look for unexpected login alerts or password-reset emails you did not request, which can signal that someone is trying your leaked credentials.
