Data breach
LiveJournal
- Records
- 33,715,538
- Breach date
- 1 January 2017Estimated
- Added
- 1 December 2024
What was exposed
3 types of data · 1 puts you at serious risk
- Email addresses33,715,538
- Websites33,715,538
- Passwords32,926,316
About this breach
In 2017, the blogging platform LiveJournal suffered a data breach, but the scale of the incident only became public years later. According to our investigation team, the breach involves records for roughly 33.7 million LiveJournal accounts, with email addresses and passwords exposed. LiveJournal never confirmed the breach itself. News of it first surfaced in mid-2019, and in May 2020 a full data dump began circulating on hacker forums, according to reporting by BleepingComputer. BleepingComputer noted that the passwords in the dump had been converted from MD5 hashes to plain text, and that several people independently confirmed old account details from the file were accurate.
Limited public reporting: As of September 25, 2026, detailed company notices or major news coverage for this listing were limited in sources reviewed. The facts below rely primarily on the indexed fields plus any secondary sources cited.
October 2018: Dreamwidth, a journaling service based on the LiveJournal codebase, reported that users had begun receiving spam extortion emails that included real passwords, according to Help Net Security.
Mid-2019: News of the alleged LiveJournal breach began to circulate publicly.
May 2020: A data dump containing more than 26 million unique LiveJournal accounts was shared for free on multiple hacker forums, as reported by BleepingComputer.
What Information Was Compromised?
Our analysis found the following data types in this breach: email addresses, passwords, and website URLs.
Not every individual is affected by every type of data listed here.
The website URLs correspond to users' LiveJournal profile pages. Secondary reporting on the circulating dump also described usernames and plain-text passwords among the exposed records. Because LiveJournal never issued a confirmed breach notice, the full set of compromised fields cannot be independently verified.
What Are the Potential Risks for Affected Individuals?
The biggest risk is password reuse. If you used the same password on LiveJournal and on email, banking, shopping, or social media accounts, attackers can try those credentials elsewhere. This technique, known as credential stuffing, was already being observed against related services. Dreamwidth administrators reported that credentials from this database were used in credential-stuffing attacks as early as 2017 and 2018, according to BleepingComputer.
Plain-text passwords make this dump immediately usable. There is no cracking step required, so anyone with the file can attempt logins right away. The exposure of email addresses also enables targeted phishing, including extortion messages that reference real passwords. Dreamwidth reported users receiving exactly this kind of spam email in October 2018.
What Is LiveJournal Doing in Response?
LiveJournal has not confirmed that a breach occurred. BleepingComputer reported that the company never acknowledged the incident or verified the database as legitimate, and did not respond to an emailed request for comment. Denise Paolucci, an owner of Dreamwidth, said her team contacted LiveJournal several times about the circulating file and that LiveJournal responded each time that the situation did not warrant disclosure to its users. She advised people to treat the file as legitimate and assume any past LiveJournal password may be compromised.
What Should You Do If You Were Affected?
Change your LiveJournal password now, even if you have not used the account in years.
If you reused that password anywhere else, change it on those accounts too, starting with email and financial services.
Use a unique, long password for every account, and store them in a password manager.
Turn on two-factor authentication wherever it is offered.
Be cautious with emails referencing your password or your LiveJournal account. Extortion scams often cite old breached credentials to sound convincing.
Watch for phishing attempts that use your exposed email address.
Because the breach may date back to 2017, some users may have already retired the affected passwords. Checking and updating is still worthwhile if there is any doubt.
In the news
- BleepingComputer: 26 million LiveJournal accounts being shared on hacker forumsbleepingcomputer.com (opens in a new tab)
- Help Net Security: Account credentials of 26+ million LiveJournal users leaked onlinehelpnetsecurity.com (opens in a new tab)
- ThreatPost: Hackers Sell Data from 26 Million LiveJournal Users on Dark Webthreatpost.com (opens in a new tab)
