Data breach
Dailymotion
- Records
- 85,199,391
- Breach date
- 20 October 2016Estimated
- Added
- 1 December 2024
What was exposed
3 types of data · 1 puts you at serious risk
- Usernames85,199,388
- Email addresses85,194,606
- Passwords1,193,682
About this breach
In October 2016, the French video-sharing platform Dailymotion lost a large portion of its user account database to an outside attacker. According to our investigation team, the compromised dataset contains more than 85 million records, including roughly 85.2 million usernames and email addresses and about 1.19 million password entries. The breach came to public attention in December 2016, when the breach notification service LeakedSource announced it had received the stolen database. At the time, Dailymotion confirmed in a company blog post that a security risk coming from outside the platform may have compromised passwords for a number of accounts, while stating that the impact was limited and that no personal information beyond account credentials had been lost.
Breach Timeline
October 20, 2016: The date the attack on Dailymotion's user database is estimated to have occurred, according to reporting by LeakedSource and coverage by BBC News.
December 5, 2016: LeakedSource publicly announced that it had received a database of Dailymotion accounts, and ZDNet independently confirmed the data was genuine, as reported by Nextgov.
December 2016: Dailymotion published a blog post acknowledging the incident and advising all users to change their passwords, per BBC News and Telecompaper.
What Information Was Compromised?
Our analysis found the following data types in this breach: usernames (nicknames) for nearly all 85.2 million records, email addresses for about 85.19 million records, and roughly 1.19 million password entries.
Contemporaneous reporting adds context on how passwords were stored. According to BBC News and SecurityAffairs, about 18 million accounts included password hashes protected with the Bcrypt algorithm and multiple rounds of key stretching, a scheme designed to make cracking passwords difficult. No physical addresses, payment details, or other personal information were reported stolen.
Not every individual is affected by every type of data listed here.
What Are the Potential Risks for Affected Individuals?
The most direct risk involves the email addresses. With tens of millions of addresses in circulation, attackers can use them for phishing emails that appear more convincing because they reference a service the recipient actually uses. The addresses can also be targeted with spam campaigns.
If a password from this breach matches a password you reused on other websites, criminals could try those credentials on email, banking, shopping, and social media accounts, a technique known as credential stuffing. The Bcrypt hashing reported at the time reduces the odds that the stored passwords can be recovered, but it does not eliminate the risk, particularly for weak or common passwords.
What Is Dailymotion Doing in Response?
Dailymotion responded publicly in December 2016 through a blog post in which it said a potential security risk from outside the company may have compromised passwords for a certain number of accounts. The company advised all users to change their passwords, offered guidance on choosing strong passwords, and suggested users could rely on token-based authentication. It also stated that it believed the impact of the breach was limited and that no personal information had been lost, according to BBC News and Telecompaper.
What Should You Do If You Were Affected?
If you had a Dailymotion account before late 2016, take these precautions:
Change your Dailymotion password if you have not done so since the breach, even though the company may not have required it.
If you reused that password anywhere else, change it on every other site where it appeared. Each account should have a unique password.
Use a password manager to generate and store strong, distinct passwords.
Turn on two-factor authentication wherever it is offered, especially on your email account.
Be cautious with emails claiming to come from Dailymotion or referencing your account, and avoid clicking links or entering credentials through emailed links.
Watch for unusual sign-in attempts or password reset messages you did not request.
In the news
- BBC News: Millions of Dailymotion account details takenbbc.com (opens in a new tab)
- Nextgov: 85M User Accounts Compromised from Video-sharing Site Dailymotionnextgov.com (opens in a new tab)
- Telecompaper: Dailymotion admits security breach on customer passwordstelecompaper.com (opens in a new tab)
- SecurityAffairs: 85 Million user accounts stolen from the Video-sharing website Dailymotionsecurityaffairs.com (opens in a new tab)
- LeakedSource: DailyMotion.com Data Breachleakedsource.com
