Data breach
Gawker
- Records
- 531,350
- Breach date
- 11 December 2010Estimated
- Added
- 24 July 2026
What was exposed
1 type of data · 1 more reported
- Email addresses1
- PasswordsReported, not counted
Reported in the breach write-up; not counted in the analysed data.
About this breach
In December 2010, hackers broke into the servers of Gawker Media, the publisher of Gawker.com and its sister sites Gizmodo and Jezebel, and stole the user database for the company's commenting system. The group, which called itself Gnosis, released more than 1.3 million registered user accounts online, including usernames, email addresses, and password files. Our investigation team's index for this listing contains 531,350 rows, with email addresses among the exposed data. Gawker's own databases, source code for its content management system, and internal files belonging to employees were also taken. Gawker's estimated attack date is December 11, 2010.
Breach Timeline
December 11, 2010: The Gnosis hacking group compromised Gawker Media's servers during a weekend attack, defaced its sites, and published user account data, source code, and internal documents online, according to The New York Times and Wikipedia's account of the incident.
December 15, 2010: Yahoo, Twitter, and LinkedIn asked affected users to change their passwords after the breach, and analysis found that the most common Gawker user passwords were "123456," "password," and "12345678," per BBC News.
December 29, 2010: The Guardian reported, citing sources linked to Gnosis, that the hackers had held access to Gawker's content management system for roughly six months, far longer than the few days Gawker initially claimed, and had exploited a local file inclusion vulnerability to get in.
What Information Was Compromised?
Our analysis found the following data types in this breach: email addresses, along with usernames and password hashes for Gawker and affiliated site accounts.
The stolen password file used DES-based crypt(3) hashes, a weak and long-outdated encryption method. Security researchers and the hackers themselves cracked hundreds of thousands of passwords through dictionary attacks, because many users had chosen simple words like "password" or "123456." The hackers also published Gawker Media's website source code and internal material, including correspondence among staff. Gawker founder Nick Denton was among those whose credentials were exposed, and the attackers used a reused password to reach the company's internal Campfire chat system.
Not every individual is affected by every type of data listed here.
What Are the Potential Risks for Affected Individuals?
The main risk is password reuse. Because Gawker stored passwords with weak DES encryption, many were recovered in plain text, and any user who reused the same password on email, banking, shopping, or social media accounts could have those accounts accessed by anyone holding the leaked file. That risk materialized quickly: after the breach, attackers used matching Gawker email and password combinations to take over Twitter accounts and spam their followers with advertisements, according to Wikipedia's summary of the incident and reporting at the time.
Exposed email addresses also support phishing. People in the database could be targeted with convincing emails claiming to come from Gawker, Twitter, LinkedIn, or other services, asking them to reset passwords or click malicious links.
What Is Gawker Doing in Response?
Gawker told users on its sites that "our user databases appear to have been compromised" and advised them to change their Gawker passwords and any reused passwords elsewhere, as reported by The New York Times. Days later, Gawker's technology chief circulated a memo, published by The Next Web and covered by The Register, acknowledging the site's security failures and outlining plans to overhaul its infrastructure, require two-factor authentication for employees accessing sensitive systems, and mandate encrypted connections for Gawker accounts on Google Apps.
What Should You Do If You Were Affected?
Change your password on any Gawker Media site account, including Gawker, Gizmodo, and Jezebel, if you still use one.
Change passwords on any other account where you used the same or a similar password, starting with your primary email, banking, and social media accounts.
Watch for phishing emails referencing Gawker or password resets, and do not click links in unexpected messages.
Enable two-factor authentication where services offer it.
In the news
- The New York Times, "Hackers Disrupt Sites Run by Gawker Media" (December 13, 2010)nytimes.com (opens in a new tab)
- The Guardian, "Gawker falls victim to hackers" (December 13, 2010)theguardian.com (opens in a new tab)
- BBC News, "Gawker hack triggers password resets at major sites" (December 2010)bbc.com (opens in a new tab)
- The Guardian, "Gawker was hacked six months ago, say sources close to Gnosis" (December 29, 2010)theguardian.com (opens in a new tab)
- The Register, "Gawker tech boss admits site security was crap" (December 18, 2010)theregister.com
