Data breach
iSpeak
- Records
- 8,532,924
- Breach date
- 1 January 2011Estimated
- Added
- 1 December 2024
What was exposed
3 types of data · 1 puts you at serious risk
- Email addresses8,532,924
- Usernames8,532,900
- Passwords8,527,376
About this breach
A dataset containing information from millions of accounts on iSpeak.cn, a Chinese voice-based online community, circulated among hackers and leaked onto the public internet in late December 2011. The indexed dataset holds 8,532,924 rows, including more than 8.5 million email addresses, roughly 8.53 million nicknames, and over 8.52 million passwords. The team estimates the underlying breach occurred around January 1, 2011, though the exact attack date could not be confirmed. The data surfaced as part of a much larger wave of leaks that hit major Chinese websites that month, when databases from sites such as CSDN and Tianya were posted online, many with passwords stored in readable plain text.
Limited public reporting: As of September 25, 2026, detailed company notices or major news coverage for this listing were limited in sources reviewed. The facts below rely primarily on the indexed fields plus any secondary sources cited.
December 21, 2011: The leak wave began when Qihoo 360 disclosed that a file with millions of CSDN user credentials, including plain-text passwords, had been posted online, according to China Daily.
December 26, 2011: Datasets attributed to iSpeak.cn began circulating publicly; a widely shared compilation of the December 2011 leaks lists iSpeak account data and describes the passwords as stored in plain text.
What Information Was Compromised?
Our analysis found the following data types in this breach: email addresses, nicknames, and passwords. Contemporaneous compilations of the December 2011 leaks described the iSpeak passwords as plain text, meaning they were not scrambled or encrypted and could be read directly by anyone holding the file.
Not every individual is affected by every type of data listed here.
What Are the Potential Risks for Affected Individuals?
The main danger from a leak like this is password reuse. Many people use the same password, or small variations of it, across email, shopping, banking, and social media accounts. If a password from iSpeak matches a password someone still uses elsewhere, an attacker can try those credentials on other sites, a technique known as credential stuffing. Automated tools make it easy to test millions of leaked email-and-password pairs against popular services.
Exposed email addresses also fuel phishing. Scammers can send messages that appear to come from a legitimate service, referencing details that make the message look credible, and trick recipients into handing over more information or clicking malicious links. Because the passwords were reportedly unencrypted, there is no barrier protecting them once the file is out. The data has now circulated for well over a decade, so anyone who has reused an old password should assume it is effectively public.
What Should You Do If You Were Affected?
Change your password on iSpeak.cn if you still have an account there.
Change the password anywhere else you used the same or a similar password, starting with your primary email account.
Use a long, unique password for each important account, and consider a password manager to keep track of them.
Turn on two-factor authentication wherever a service offers it, especially for email and financial accounts.
Be cautious with unexpected emails or messages that ask you to log in, verify an account, or click a link. Treat any message referencing an old iSpeak account as a possible phishing attempt.
