Data breach
csdn.net
- Records
- 6,428,632
- Breach date
- 1 January 2011Estimated
- Added
- 12 February 2025
What was exposed
3 types of data · 1 puts you at serious risk
- Usernames6,428,630
- Passwords6,428,617
- Email addresses6,426,203
About this breach
In December 2011, a file containing more than 6.4 million user accounts from CSDN.net, one of China's largest software developer communities, spread across the internet. The indexed dataset contains 6,428,632 rows, and the passwords in it were stored in plain, unencrypted text. The dump surfaced on December 21, 2011, and quickly became the largest confirmed data leak in China's internet history at that point, touching off a wave of copycat claims against other Chinese websites.
CSDN, operated by Beijing-based companies, confirmed within days that the data was real. The company said the leaked database was an older backup, that most plaintext passwords predated an April 2009 switch to encrypted storage, and that it had reported the incident to police. Beijing police later determined a hacker used flaws in CSDN's system to enter its database and extract user data in April 2010, more than a year before the dump went public. The investigation team estimates the attack date as January 2011.
April 2010: A hacker, later identified by Beijing police only as Zeng, exploited flaws in CSDN's systems and entered the user database, according to admissions he made after his arrest.
December 21, 2011: A file with roughly 6 million CSDN usernames, plaintext passwords, and email addresses appeared online, and CSDN reported the breach to Beijing police.
December 28, 2011: China's Ministry of Industry and Information Technology issued a public notice condemning the theft and disclosure of user data and said it had activated an emergency response plan.
February 4, 2012: Police arrested the suspect surnamed Zeng in Wenzhou, Zhejiang Province.
March 2012: Beijing police announced the case was solved, detained five suspects on charges of illegally obtaining computer data, and issued CSDN an administrative warning for failing to meet national information security requirements, the first such penalty under regulations in force since 2007.
What Information Was Compromised?
Our analysis found the following data types in this breach: usernames or nicknames, passwords stored in plaintext, and email addresses. The dataset covers 6,428,630 username records, 6,428,617 password records, and 6,426,203 email records, according to the investigation team.
Because passwords were not hashed or encrypted, anyone who obtained the file could read them directly. CSDN's own statements confirmed that passwords created before April 2009 were stored in plaintext and that the leaked accounts were registered before September 2010.
Not every individual is affected by every type of data listed here.
What Are the Potential Risks for Affected Individuals?
The main risk is password reuse. Security researchers who examined the leak found that many people used the same credentials on other sites, so a leaked CSDN password could open email, shopping, gaming, social networking, and even financial service accounts. Attackers can run automated "credential stuffing" attempts against other websites using the leaked username and password pairs. Plaintext passwords also expose weak habits, such as common dictionary words, which makes accounts easier to guess. The email addresses themselves can be used for targeted phishing, since a message that knows your username and password history looks more convincing.
What Is csdn.net Doing in Response?
CSDN responded quickly after the dump appeared. The company issued a public apology and an official statement, urged users to change their CSDN passwords and any reused passwords elsewhere, emailed affected users registered before September 2010, temporarily disabled logins, and forcibly reset passwords for accounts found in the leak. It said it had moved its 20 million registered user accounts to encrypted storage with backups and had contacted major Chinese internet and email providers, including Tencent, NetEase, and Alipay, to warn their users. Beijing police later issued CSDN an administrative warning for inadequate security practices and required remediation.
What Should You Do If You Were Affected?
If you had a CSDN account registered before roughly September 2010, assume your password was exposed and change it everywhere it was reused, starting with your email account. Enable two-factor authentication where services offer it. Watch for phishing emails that reference your CSDN username or account activity, and never enter credentials from an emailed link. A password manager can help you create and track unique passwords for each site.
In the news
- ZDNet: Chinese hacker arrested for leaking 6 million loginszdnet.com (opens in a new tab)
- Global Times: Hacker arrested over IT database leakglobaltimes.cn (opens in a new tab)
- Slashdot: Chinese Developer Forum Leaks 6 Million User Credentialsit.slashdot.org (opens in a new tab)
- Aliyun Developer Community: CSDN six million user data leakdeveloper.aliyun.com (opens in a new tab)
