Data breach
CashCrate
- Records
- 6,892,355
- Breach date
- 17 November 2016Estimated
- Added
- 17 March 2025
What was exposed
7 types of data · 1 puts you at serious risk
- Account balances6,892,355
- Passwords6,892,111
- Email addresses6,891,487
- Names6,324,741
- Home addresses5,882,941
- Phone numbers1,871,114
- Usernames505,190
About this breach
In November 2016, CashCrate, a website that paid users to complete online surveys and small tasks, lost a user database containing roughly 6.89 million records, according to the investigation team. The breach stayed quiet for months. It became public in June 2017, when the stolen database surfaced and was reported on by Motherboard, Vice's technology desk, after the outlet obtained a copy of the data. The company told Motherboard at the time that it believed attackers had compromised a third-party forum plug-in, which it said it had deactivated while it investigated.
What Information Was Compromised?
Our analysis found the following data types in this breach: passwords (6,892,111 records), email addresses (6,891,487), account balances (6,892,355), names (6,324,741), home addresses (5,882,941), phone numbers (1,871,114), and nicknames or usernames (505,190).
Not every individual is affected by every type of data listed here.
Reporting by Motherboard added important context about how the passwords were stored. The oldest accounts, some dating back to 2006, appeared to have passwords kept in plain text. Accounts created from around mid-2010 onward used MD5 hashes, a hashing method widely considered weak and relatively easy to crack. In a statement to Motherboard, a CashCrate spokesperson said users who had logged in since October 2013 had passwords that were fully hashed and salted, and that the company was looking into why some inactive accounts still held plain text passwords, which it said would be hashed immediately.
The presence of physical addresses, phone numbers, and account balances alongside email credentials makes this leak more sensitive than a typical password dump. Because CashCrate paid users real money, the account balances in particular could signal which accounts were worth targeting.
What Are the Potential Risks for Affected Individuals?
The most immediate risk is password reuse. Many people use the same password across multiple sites, so credentials from CashCrate can be tested against email, banking, and social media accounts. Attackers routinely run these automated login attempts, known as credential stuffing, against lists from old breaches.
The personal details in the leak also support targeted phishing. A scammer holding a person's name, home address, and email address can craft convincing messages that appear legitimate, including fake payment or account notices. People who earned money on the site could be misled by references to their balance or payment history. Home addresses and phone numbers additionally open the door to harassment, spam, and identity fraud when combined with other leaked data.
What Is CashCrate Doing in Response?
According to Motherboard's June 2017 report, CashCrate said it was in the process of notifying all members about the breach. A spokesperson told the outlet that the company believed its third-party forum software had been compromised, that the software had been deactivated until it was confident it was secure, and that plain text passwords in inactive accounts would be hashed and salted. No further public response from the company has been verified in the sources reviewed for this article.
What Should You Do If You Were Affected?
If you had a CashCrate account, take these steps:
Change your CashCrate password if the account still exists, and change it anywhere else you reused that password.
Prioritize your email account, since it can be used to reset passwords on almost everything else.
Turn on two-factor authentication wherever it is offered, especially for email and banking.
Watch for phishing emails that reference surveys, payments, or your personal details, and never click reset links you did not request.
Consider reviewing your financial statements and credit reports for unfamiliar activity, given that physical addresses were part of the leak.
Be cautious with unexpected calls or texts; phone numbers were included in the exposed data.
