Data breach
Etsy
- Records
- 3,601
- Breach date
- 31 May 2023Estimated
- Added
- 5 December 2024
What was exposed
5 types of data · 1 puts you at serious risk
- Names3,601
- Home addresses3,600
- Social security numbers3,539
- Email addresses1,925
- Phone numbers593
About this breach
Etsy, the online marketplace for handmade and vintage goods, appears in a newly indexed data breach listing. The incident is estimated to have occurred on May 31, 2023, and involves roughly 3,601 records. No claiming actor has come forward, and the listing was added to the database on December 5, 2024.
Limited public reporting: As of September 25, 2026, detailed company notices or major news coverage for this listing were limited in sources reviewed. The facts below rely primarily on the indexed fields plus any secondary sources cited.
Without an official statement from Etsy, it is not clear how the data was obtained, whether it came directly from Etsy's systems, or how widely it circulated before being indexed.
What Information Was Compromised?
Our analysis found the following data types in this breach:
Names (3,601 records)
Home addresses (3,600 records)
Social Security numbers (3,539 records)
Email addresses (1,925 records)
Phone numbers (593 records)
Not every individual is affected by every type of data listed here.
The presence of Social Security numbers alongside home addresses is the most concerning combination in this listing. That pairing is not typical of routine e-commerce records and materially raises the risk of identity fraud for the affected individuals.
What Are the Potential Risks for Affected Individuals?
The most serious risk is identity theft. A Social Security number combined with a full name and home address is essentially the core package a fraudster needs to open new lines of credit, file fraudulent tax returns, or apply for loans and government benefits in someone else's name.
Email addresses and phone numbers also enable targeted phishing. Attackers who know a person shops on Etsy can send convincing messages about fake orders, shop suspensions, or account verifications designed to steal passwords or payment details.
Because the breach is estimated to have occurred in May 2023 but the listing was only indexed in December 2024, any misuse could have been underway for well over a year before the exposure became visible. Individuals affected by this breach should review their records with extra attention to older, hard-to-spot activity.
What Should You Do If You Were Affected?
If you believe your information may be in this breach, take these steps:
Place a fraud alert or credit freeze. Contact one of the three major credit bureaus (Equifax, Experian, or TransUnion); placing an alert with one notifies the others. A freeze is free and blocks most new credit from being opened in your name.
Review your credit reports. You can request free reports from all three bureaus at AnnualCreditReport.com and look for accounts or inquiries you do not recognize.
Watch for IRS-related fraud. If a tax return is rejected because one was already filed in your name, contact the IRS immediately and consider filing Form 14039, the Identity Theft Affidavit.
Secure your Etsy account. Change your Etsy password and enable two-factor authentication if you have not already. Change the password anywhere else you reused it.
Be skeptical of Etsy-themed messages. Do not click links in unexpected emails or texts about orders, disputes, or account problems. Go directly to etsy.com instead.
Monitor financial statements. Check bank and card statements regularly for charges you did not authorize.
