Data breach
Brazzers
- Records
- 800,004
- Breach date
- 1 April 2013Estimated
- Added
- 1 December 2024
What was exposed
2 types of data · 1 more reported · 1 puts you at serious risk
- Email addresses1
- Passwords1
- UsernamesReported, not counted
Reported in the breach write-up; not counted in the analysed data.
About this breach
Nearly 800,000 accounts tied to the adult website Brazzers surfaced online in a data dump that our investigation team estimates dates back to April 1, 2013. The listing, indexed by our team on December 1, 2024, contains about 800,004 rows of account records. The records did not come from a direct break-in of Brazzers itself, but from Brazzersforum, a discussion site for the brand that was operated by a third party and built on vBulletin forum software.
The story stayed quiet for years. The stolen data was reportedly posted in April 2013 and went largely unnoticed until September 2016, when the technology publication Motherboard, working with the breach monitoring site Vigilante.pw, reported on the dump. Mainstream outlets including the BBC and SC Magazine then covered the disclosure. According to SC Magazine, the full dump contained 928,072 accounts including duplicates, covering 790,724 unique email addresses, along with usernames and passwords stored in plain text.
April 2013: The data dump was posted online, where it went undetected for more than three years, according to SC Magazine.
September 2016: Motherboard, tipped by Vigilante.pw, publicly reported the leak; BBC News and other outlets followed.
What Information Was Compromised?
Our analysis found the following data types in this breach: email addresses and passwords.
The external reporting adds more detail. SC Magazine states the dump also included usernames, and that the passwords appeared in plain text rather than in scrambled or encrypted form, which makes them directly usable by whoever holds them.
Not every individual is affected by every type of data listed here.
Brazzers told Motherboard that the leaked records matched data from a 2012 security incident at its forum. The company also said that because Brazzers and the forum shared account information for user convenience, some people who never registered on the forum were exposed as well.
What Are the Potential Risks for Affected Individuals?
Plain-text passwords are the most serious problem here. Anyone holding this dump can log into accounts protected by those passwords without needing to crack anything first.
The risks extend beyond Brazzers. Because many people reuse the same password across sites, a leaked credential from the forum could open email, banking, shopping, or social media accounts. Attackers commonly run "credential stuffing" attacks, feeding stolen email and password pairs into login forms across hundreds of other websites. Email addresses in the dump can also be used for targeted phishing, since attackers know the recipients had accounts on an adult site, which makes for convincing blackmail or sextortion-style scams. Reporting on this incident came years after the theft, so any affected person's password may have circulated among criminals for a long time.
What Is Brazzers Doing in Response?
Brazzers responded when the leak became public in 2016. The company told Motherboard that it took corrective measures in the days after learning of the underlying incident, and that it banned all non-active accounts listed in the data set so the exposed usernames and passwords could no longer be used. The company said the forum involved was run by a third party and attributed the intrusion to a vulnerability in vBulletin software.
What Should You Do If You Were Affected?
If you had an account with Brazzers or its forum, take these steps:
Change your password on Brazzers immediately, and anywhere else you used the same or a similar password.
Choose a long, unique password for every account, and consider a password manager to keep track of them.
Turn on two-factor authentication wherever it is offered, especially on your email account.
Be cautious with unexpected emails that reference your account or the site, since leaked email addresses feed phishing campaigns. Do not click links or open attachments in suspicious messages.
Watch for account activity you did not authorize, and treat any sextortion or blackmail email as a scam rather than paying or responding.
