Data breach
DaFont
- Records
- 661,741
- Breach date
- 16 May 2017Estimated
- Added
- 1 December 2024
What was exposed
2 types of data · 2 more reported · 1 puts you at serious risk
- Email addresses661,741
- Passwords661,165
- UsernamesReported, not counted
- Private messagesReported, not counted
Reported in the breach write-up; not counted in the analysed data.
About this breach
An attacker stole a database belonging to DaFont, a popular website for downloading free fonts, in May 2017, exposing hundreds of thousands of user accounts. According to our investigation team, the listing contains 661,741 records, including 661,741 email addresses and 661,165 passwords. The estimated attack date is May 16, 2017. External reporting at the time described roughly 699,464 accounts, including usernames, email addresses, and hashed passwords.
Breach Timeline
May 16, 2017: Estimated date of the breach, when the site's database was compromised via a SQL injection flaw.
May 18, 2017: French technology outlet KultureGeek reported the theft, and Mozilla Monitor records the breach as verified and added to its database on this date.
May 19, 2017: Further coverage, including from IT Security Guru, detailed the scale of the theft.
According to Tripwire and Bitdefender, the attacker exploited what they described as an easy-to-find union-based SQL injection vulnerability in the site's software and said the attack was carried out mainly for challenge and practice. The database had been stored using MD5, an outdated and weak password-hashing method with no added salt, and the attacker reportedly converted about 98 percent of the stored passwords into readable text. The stolen database also included forum content, and reporting noted that corporate email accounts from Microsoft, Google, and Apple, along with accounts tied to United States and United Kingdom government agencies, appeared among the affected addresses. No individual or group has claimed responsibility for the breach in our listing.
What Information Was Compromised?
Our analysis found the following data types in this breach: email addresses and passwords.
Not every individual is affected by every type of data listed here.
External reporting from 2017 additionally described the theft of usernames and forum data, including private messages, though these fields are not part of our indexed record count.
What Are the Potential Risks for Affected Individuals?
The main risk is that most passwords in the stolen database were crackable, and many were converted to readable form. Anyone who reused the same password on other sites faces a real chance of account takeover through credential stuffing, where attackers try leaked email and password pairs against other services.
Exposed email addresses can also fuel phishing, with messages crafted to look like legitimate password reset requests or DaFont-related notices. Where corporate or government email accounts were involved, the exposure raised broader security concerns for those organizations. Because the database included forum activity and private messages, affected users could also face targeted social engineering based on what they had written.
What Is DaFont Doing in Response?
DaFont addressed the breach in a post on its own forum. In that post, the site confirmed the database was hacked in May 2017, said passwords are now encrypted in a more secure way, and stated that every user was forced to change their password the next time they logged in. The site also noted that any readable passwords tied to an account would have been set before 2017, when MD5 hashing was still in use. There is no record of a more detailed public incident report.
What Should You Do If You Were Affected?
Change your DaFont password immediately if you have not done so since 2017, and make it long and unique.
If you used that same password anywhere else, change it on those accounts too. Password reuse is what turns one breach into many.
Turn on two-factor authentication wherever the service offers it, especially for email accounts, which often control password resets for everything else.
Watch for phishing emails that reference DaFont, font downloads, or account problems, and never enter your password through a link in an email.
