Data breach
imgur
- Records
- 1,755,560
- Breach date
- 1 September 2013Estimated
- Added
- 1 December 2024
What was exposed
2 types of data · 1 puts you at serious risk
- Email addresses1,755,560
- Passwords1,755,505
About this breach
In late November 2017, Imgur confirmed that hackers had stolen the email addresses and passwords of about 1.7 million user accounts in an intrusion that dated back years. The image-sharing company said it first learned of the breach on November 23, 2017, when an outside security researcher sent the company a sample of stolen credentials. The indexed dataset for this incident contains roughly 1.76 million records, with email addresses on essentially all of them and passwords on all but a small fraction. The team estimates the attack itself occurred around September 2013, while Imgur's own disclosure at the time described it as a 2014 incident, a discrepancy the company never fully resolved publicly.
Breach Timeline
September 2013: the investigation team estimates the breach occurred around this date, based on the indexed records.
November 23, 2017: Imgur was alerted to the breach by an outside security researcher who shared stolen account data with the company, according to TechCrunch and SC Media.
November 24, 2017: Imgur began notifying affected users by email, forced password resets, and published a public disclosure on its blog, per ZDNet.
What Information Was Compromised?
Our analysis found the following data types in this breach:
Email addresses, present on all 1,755,560 records indexed
Passwords, present on 1,755,505 records
Imgur's own disclosure stated that no other personal data was taken. The company noted it has never asked users for real names, addresses, or phone numbers, so no such information was involved.
A key technical detail matters here. At the time of the breach, Imgur stored passwords as SHA-256 hashes without a salt, a weaker method than modern standards. In the stolen dataset, many passwords appeared in plain text, which suggests attackers had cracked the original hashes, as reported by SC Media. Imgur said it switched to the stronger bcrypt algorithm in 2016.
Not every individual is affected by every type of data listed here.
What Are the Potential Risks for Affected Individuals?
The main risk is credential abuse. Because the exposed passwords appear to have been cracked, anyone who used the same email and password combination on other services could face account takeovers elsewhere. Attackers routinely test leaked credentials against email providers, banking sites, and social media in automated "credential stuffing" attacks.
Email addresses in the wrong hands also enable targeted phishing. Someone posing as Imgur, or as another service you use, can send convincing messages designed to trick you into revealing more information. These risks persist long after a breach because stolen credential lists circulate for years. This dataset surfaced roughly four years after the intrusion itself.
What Is imgur Doing in Response?
Imgur responded quickly once it learned of the breach. On November 24, 2017, it began emailing affected users and forcing password resets on compromised accounts, according to TechCrunch. Chief operating officer Roy Sehgal published a disclosure apologizing for the incident, and the company said it was still investigating how the intrusion happened. ZDNet reported that Imgur planned to notify the California attorney general, law enforcement, and other relevant agencies. The company also pointed to its 2016 move to bcrypt password hashing as an improvement made since the breach.
What Should You Do If You Were Affected?
If you had an Imgur account in or before 2017, take these steps:
Change your Imgur password immediately if you have not done so since late 2017.
If you reused that password anywhere else, change it on every other account.
Use unique passwords for each service. A password manager can generate and store them.
Turn on two-factor authentication wherever it is offered, especially on your email account.
Be cautious with emails claiming to come from Imgur or other services, and avoid clicking links or entering credentials through unexpected messages.
In the news
- TechCrunch: Imgur says 1.7M emails and passwords were breachedtechcrunch.com (opens in a new tab)
- ZDNet: Imgur confirms it was hackedzdnet.com (opens in a new tab)
- BBC News: Imgur confirms 1.7 million users hit by data breachbbc.com (opens in a new tab)
- SC Media: Imgur acts fast to disclose years-old breachscworld.com (opens in a new tab)
- Sophos: Imgur wasn't storing your passwords properlynews.sophos.com
