Data breach
Evite
- Records
- 36,194,032
- Breach date
- 11 August 2013Estimated
- Added
- 1 December 2024
What was exposed
5 types of data · 3 more reported · 1 puts you at serious risk
- Names36,177,724
- Passwords36,115,399
- Email addresses1,513,586
- Home addresses84,834
- Biographies3,821
- UsernamesReported, not counted
- Dates of birthReported, not counted
- Phone numbersReported, not counted
Reported in the breach write-up; not counted in the analysed data.
About this breach
Evite, the online invitation service, exposed personal data belonging to tens of millions of people in a breach that traces back to August 11, 2013. According to our investigation team, the indexed dataset contains more than 36.1 million records, including about 36.1 million passwords and 36.2 million names. The intrusion went undetected for years. It surfaced publicly in 2019 when a hacker began selling the Evite data on dark web marketplaces, and the company confirmed the incident in a notice to customers that June. This listing was added to our index on December 1, 2024.
August 11, 2013: The estimated date of the breach, when the old user data was created, per our investigation team and Mozilla Monitor.
February 22, 2019: Evite's investigation traced the start of the malicious activity to this date, according to the company's notice filed with the Delaware Attorney General.
April 15, 2019: Evite became aware of the data security incident, the company's notice states.
May 14, 2019: The investigation determined that an unauthorized party had acquired an inactive data storage file containing user accounts with information created up through 2013.
June 10, 2019: Evite sent a notice of data breach to affected customers and set up a dedicated call center.
What Information Was Compromised?
Our analysis found the following data types in this breach: passwords (36,115,399), names (36,177,724), email addresses (1,513,586), home addresses (84,834), and biographical entries (3,821).
The company's notice filed with the Delaware Attorney General described the stolen file as containing names, usernames, email addresses, Evite passwords, and, where users had provided them optionally, dates of birth, phone numbers, and mailing addresses. Evite said no financial information or Social Security numbers were in the file.
Not every individual is affected by every type of data listed here.
External reporting, including coverage by CBS News, put the number of affected accounts above 100 million, many of them invitation recipients rather than registered users. Passwords were stored in plain text, which means anyone who obtained the file could read them directly.
What Are the Potential Risks for Affected Individuals?
Plain-text passwords are the most immediate danger. Anyone who reused an Evite password on other accounts, such as email, banking, or social media, faces a real risk that those accounts could be accessed through credential stuffing, where attackers try leaked passwords across many services.
The stolen names, email addresses, phone numbers, and home addresses can also fuel phishing. Scammers can use real details to make fake emails, texts, or calls look convincing, for example by posing as Evite or another company and asking for personal information. Address data can support targeted fraud and identity theft attempts, particularly when combined with dates of birth. Because the data circulated on dark web marketplaces in 2019, it may remain in the hands of multiple actors years later.
What Is Evite Doing in Response?
According to the company's June 2019 notice, Evite engaged external forensic consultants after discovering the incident, coordinated with law enforcement, and introduced additional security measures. The company reset users' passwords on their next login and set up a dedicated call center for questions. Evite also published an FAQ page about the incident and stated it had no evidence that the personal information had been misused.
What Should You Do If You Were Affected?
Change your Evite password, and change the password on any other account where you used the same or a similar one.
Turn on two-factor authentication where it is offered, especially for email and financial accounts.
Watch your email and bank accounts for suspicious activity, and be wary of unsolicited messages that ask for personal information or push you to a login page.
Avoid clicking links or downloading attachments from unexpected emails.
Consider placing a fraud alert or credit freeze with the major credit bureaus if you are concerned about identity theft, since names and addresses were among the exposed data.
In the news
- Evite customer notice, Delaware Attorney General (June 10, 2019)attorneygeneral.delaware.gov (opens in a new tab)
- CBS News Texas: Evite Gives Details On Data Breach After Hacker Tries To Sell Infocbsnews.com (opens in a new tab)
- Mozilla Monitor: Evite data breach detailsmonitor.mozilla.org (opens in a new tab)
