Data breach
diet.com
- Records
- 123,179
- Breach date
- 10 August 2014Estimated
- Added
- 12 February 2025
What was exposed
1 type of data · 5 more reported
- Email addresses123,179
- PasswordsReported, not counted
- IP addressesReported, not counted
- Dates of birthReported, not counted
- UsernamesReported, not counted
- NamesReported, not counted
Reported in the breach write-up; not counted in the analysed data.
About this breach
In August 2014, the diet and nutrition website diet.com suffered a data breach that exposed user records from the platform. The indexed dataset contains 123,179 rows, with email addresses among the data found. The breach was not publicly claimed by any hacker group, and the circumstances of how the data left the company's systems remain unclear. External breach trackers have described the incident as one in which member data dating back as far as 2004 surfaced online, suggesting the records had circulated for years before the exposure was cataloged.
Limited public reporting: As of September 25, 2026, detailed company notices or major news coverage for this listing were limited in sources reviewed. The facts below rely primarily on the indexed fields plus any secondary sources cited.
Breach Timeline
August 10, 2014: The breach of diet.com occurred on this date, according to Mozilla Monitor.
October 13, 2017: The breach was discovered and verified, and added to Mozilla Monitor's database of public data exposures.
What Information Was Compromised?
Our analysis found the following data types in this breach: email addresses.
Mozilla Monitor lists additional fields tied to this incident: passwords, IP addresses, email addresses, dates of birth, usernames, and personal details described as eating habits, names, and physical attributes. Independent breach catalogs such as Leaked.Domains describe the exposed dietary information as including members' eating habits, BMI, and birth dates, with passwords stored in plain text.
Because diet.com is a weight loss and nutrition service, the exposed records may combine ordinary account details with health-adjacent information. That combination can be more sensitive than a typical email and password leak.
Not every individual is affected by every type of data listed here.
What Are the Potential Risks for Affected Individuals?
The most immediate risk is account compromise. If passwords were stored in plain text, anyone who obtained the data can read them directly, and many people reuse the same password across multiple sites. That makes credential stuffing likely, where attackers try leaked email and password pairs on banking, shopping, and social media accounts.
Phishing is a second concern. Attackers who hold email addresses tied to a weight loss service can craft convincing messages that reference dieting or health goals to trick recipients into revealing more information or installing malware.
The dietary and physical attribute data adds a quieter risk. Details about eating habits, BMI, and birth dates can support targeted scams, such as fake weight loss product offers, and can feel invasive because they touch on health information.
What Should You Do If You Were Affected?
Change your diet.com password immediately, and change it anywhere else you reused it. Use a unique password for each account.
Enable two-factor authentication on email and other important accounts where it is available.
Watch your email for phishing messages that mention dieting, weight loss products, or account problems, and do not click links or open attachments from senders you do not trust.
Check whether your email address appears in this or other breaches using a reputable breach notification service.
Be cautious with unsolicited offers related to health or weight loss that reference personal details, and consider monitoring your accounts for unfamiliar sign-in activity.
