Data breach
Justdate.com
- Records
- 24,549,178
- Breach date
- 29 September 2016Estimated
- Added
- 27 January 2025
What was exposed
2 types of data
- Email addresses24,548,846
- Names22,890
About this breach
A dataset presented as user records from the online dating service Justdate.com began circulating in 2016, and it remains one of the more contested breach listings on record. The listing contains 24,549,178 rows, including roughly 24.5 million email addresses, tied to an estimated attack date of September 29, 2016. No individual or group has claimed responsibility for the data. What makes this case unusual is that later verification work suggested much of the dataset may never have come from Justdate.com at all. According to Recent Breaches, checks with people whose details appeared in the files found that only a small portion of the records matched real information, and account holders did not recall using the service. The site reports the incident has therefore been classified as fabricated, meaning the material is unlikely to have originated from Justdate.com.
Limited public reporting: As of September 25, 2026, detailed company notices or major news coverage for this listing were limited in sources reviewed. The facts below rely primarily on the indexed fields plus any secondary sources cited.
Breach Timeline
September 29, 2016: Date of the Justdate.com breach as listed by Mozilla Monitor.
February 7, 2017: The incident was added to Mozilla Monitor's breach database after being discovered and verified.
What Information Was Compromised?
Our analysis found the following data types in this breach: 24,548,846 email addresses and 22,890 names. Mozilla Monitor lists the compromised data as email addresses, dates of birth, geographic locations, and names, based on the dataset as it circulated.
The gap between those two lists reflects the disputed nature of this dataset. Our analysis counted names in only a small fraction of the records, while external descriptions of the circulating files mention birth dates and locations as well. Because the dataset has been flagged as likely fabricated by secondary reporting, the precise contents that may have actually come from Justdate.com remain unconfirmed.
Not every individual is affected by every type of data listed here.
What Are the Potential Risks for Affected Individuals?
Even if the dataset did not come from Justdate.com, a list of 24.5 million email addresses can still cause real-world harm once it circulates. Email addresses paired with names, birth dates, or locations are useful for phishing, since scammers can reference personal details to make messages appear credible. Recipients may also see a rise in spam or targeted scam attempts. Date-of-birth and location data can support identity fraud attempts when combined with information from other sources.
The fabricated classification cuts both ways. It means the data may not reflect genuine Justdate.com accounts, but it does not mean the email addresses in the files are fake or that scammers will ignore the dataset. Lists like this circulate regardless of their provenance.
What Should You Do If You Were Affected?
Start with the basics that apply to any email exposure:
Change passwords on any accounts that share a password with the email address that appeared in the files, and use unique passwords for each account going forward.
Turn on multi-factor authentication wherever an account offers it.
Watch for phishing emails that reference Justdate.com, your personal details, or a breach, and do not click links in unexpected messages.
Be cautious with security notices that pressure you to act quickly or ask for credentials; verify any claim through the company's official website rather than a link in an email.
Consider reducing where your real email address and birth date appear, since both are commonly used to target people.
