Data breach
Bitly
- Records
- 9,316,204
- Breach date
- 8 May 2014Estimated
- Added
- 1 December 2024
What was exposed
2 types of data · 1 more reported
- Usernames9,316,200
- Email addresses9,315,650
- PasswordsReported, not counted
Reported in the breach write-up; not counted in the analysed data.
About this breach
Bitly, the URL shortening service, disclosed in May 2014 that account credentials for its users had been compromised. The breach involved more than 9.3 million records, most of which included usernames and email addresses. Bitly's chief executive announced the incident in a blog post on May 8, 2014, saying the company had "reason to believe that Bitly account credentials have been compromised" and that the exposed data included email addresses, encrypted passwords, API keys, and OAuth tokens. At the time, the company said it had no indication that any accounts had been accessed without permission. The incident drew renewed attention in October 2017, when data from the 2014 breach surfaced through a breach notification service, and Bitly addressed the resurfacing publicly.
May 8, 2014: Bitly CEO Mark Josephson published a blog post disclosing that user email addresses, encrypted passwords, API keys, and OAuth tokens had been compromised, and the company sent email notifications to affected users.
October 6, 2017: Bitly publicly responded after the 2014 breach data resurfaced through a breach notification service, stating on Twitter that a third-party service compromise had affected Bitly in 2014 and that there was "no current security threat; no action required." The company also updated its original blog post that day.
What Information Was Compromised?
Our analysis found the following data types in this breach: usernames and email addresses, drawn from more than 9.3 million indexed records. According to our investigation team, roughly 9,316,200 records contained usernames and about 9,315,650 contained email addresses.
Bitly's own notice from May 8, 2014 listed additional fields beyond those: encrypted passwords, API keys, and OAuth tokens, which users rely on to connect third-party applications to their Bitly accounts. The company did not report that payment information was involved.
Not every individual is affected by every type of data listed here.
What Are the Potential Risks for Affected Individuals?
The exposed usernames and email addresses can be used for phishing, since attackers can send messages that appear to come from a legitimate service and reference a known account. If the encrypted passwords were weakly protected or if affected users reused the same password elsewhere, criminals could attempt to log in to other accounts with those credentials.
The exposure of API keys and OAuth tokens carries its own risk: these credentials can grant access to connected accounts and applications without a password. Bitly advised users at the time to change their API keys and OAuth tokens as a precaution.
What Is Bitly Doing in Response?
Bitly disclosed the breach on May 8, 2014 through a blog post and email notifications to affected users, and posted guidance encouraging users to reset passwords, rotate API keys, and revoke OAuth tokens. In October 2017, after the 2014 data resurfaced through a breach notification service, Bitly stated that a third-party service compromise had affected the company in 2014, that there was no current security threat, and that the resurfacing contained no new information beyond what it had shared in 2014.
What Should You Do If You Were Affected?
Change your Bitly password, and change it anywhere else you used the same one.
Rotate any Bitly API keys or OAuth tokens you created, and revoke access for third-party applications you no longer use.
Be cautious with unsolicited emails that reference your Bitly account or ask you to log in through a link; go directly to the website instead.
Check whether your email address appears in this or other breaches using a reputable breach-check service, and enable two-factor authentication where it is offered.
In the news
- Hackread: Millions of Accounts From Previous Bitly and Kickstarter Breaches Exposedhackread.com (opens in a new tab)
- BankInfoSecurity: Following Disqus, Expert Discloses More Old Breachesbankinfosecurity.com (opens in a new tab)
- Trend Micro: Details on Past Data Breaches from Disqus, Bitly and Kickstarter Revealedtrendmicro.com (opens in a new tab)
- Mozilla Monitor: Bitly Data Breachmonitor.mozilla.org (opens in a new tab)
