Data breach
Nitro
- Records
- 77,149,459
- Breach date
- 28 September 2020Estimated
- Added
- 1 December 2024
What was exposed
6 types of data
- Email addresses77,149,303
- Names2,005,744
- IP addresses170,526
- Employment25,041
- Job titles21,737
- Employers12,708
About this breach
Attackers stole a large user database from Nitro Software, the Melbourne-based company behind the Nitro PDF service, in late September 2020. The incident is estimated to have occurred on September 28, 2020, and involved a dataset of roughly 77.1 million rows tied to the company's gonitro.com domain. Nitro first described the incident as a "low impact security incident" that affected no customer data, but weeks later the stolen database surfaced for sale on a hacker forum, and in early 2021 it was published for free in full. BleepingComputer, which verified the database's authenticity, reported that the records included information tied to employees at well-known organizations including Google, Apple, Microsoft, Chase, and Citibank.
Limited public reporting: As of September 25, 2026, detailed company notices or major news coverage for this listing were limited in sources reviewed. The facts below rely primarily on the indexed fields plus any secondary sources cited.
Breach Timeline
October 21, 2020: Nitro Software filed an advisory with the Australia Stock Exchange describing an "isolated security incident involving limited access to a Nitro database by an unauthorised third party," stating the database did not contain user or customer documents.
October 29, 2020: BleepingComputer, citing the cybersecurity firm Cyble, reported that a database of about 70 million user records was being auctioned on a hacking forum with a starting price of $80,000, alongside roughly 1TB of documents.
January 20, 2021: A threat actor claiming affiliation with the ShinyHunters group published the full 14GB database, containing 77,159,696 records, for free on a hacking forum.
What Information Was Compromised?
Our analysis found the following data types in this breach: email addresses, names, IP addresses, and some job-related details such as job titles and employer names. Independent reporting from BleepingComputer described the leaked database as also containing bcrypt-hashed passwords, along with titles, company names, and other system-related information.
Nitro said at the time that the database involved was primarily used for logging related to its free online document conversion services and did not contain user or customer documents, which the company said were stored separately.
Not every individual is affected by every type of data listed here.
What Are the Potential Risks for Affected Individuals?
The leaked email addresses and hashed passwords can be used for credential stuffing, where attackers try stolen password combinations on other websites, betting that people reused the same password across accounts. Even hashed passwords can be cracked if they were weak or common.
The combination of a name, email address, employer, and job title also gives scammers material for convincing phishing messages. An email that references your workplace or job can look far more legitimate than a generic one, which raises the odds that recipients click malicious links or hand over credentials. Employees of large companies appearing in the dataset could be targeted individually or through their employers.
What Is Nitro Doing in Response?
After the incident was identified, Nitro said its environment was fully secured and that it implemented a password reset as a precautionary measure, according to a company statement reported by BleepingComputer. The company also said it was communicating with customers and investigating, while maintaining that there was no evidence sensitive or financial customer data had been compromised. The company's initial characterization of the incident as low impact drew scrutiny after the much larger database surfaced for sale and later leaked publicly.
What Should You Do If You Were Affected?
Change your Nitro password if you have not already, and choose a strong, unique one you do not use anywhere else.
If you reused that password on other accounts, change those passwords too. Attackers specifically test leaked email and password pairs across banking, email, and social media sites.
Turn on two-factor authentication wherever the service offers it, especially for email, which can reset many other accounts.
Watch for phishing emails that reference Nitro, PDF documents, or your employer, and avoid clicking links or opening attachments from unexpected senders.
Consider using a password manager to generate and store distinct passwords for every account.
In the news
- BleepingComputer: Hacker leaks full database of 77 million Nitro PDF user recordsbleepingcomputer.com (opens in a new tab)
- BleepingComputer: Massive Nitro data breach impacts Microsoft, Google, Apple, morebleepingcomputer.com (opens in a new tab)
- TechNadu: Over 77 Million Nitro PDF User Records Shared Online for Freetechnadu.com (opens in a new tab)
