Data breach
Lumin PDF
- Records
- 24,369,606
- Breach date
- 1 April 2019Estimated
- Added
- 1 December 2024
What was exposed
2 types of data · 2 more reported
- Names21,858,271
- Email addresses15,355,897
- PasswordsReported, not counted
- GenderReported, not counted
Reported in the breach write-up; not counted in the analysed data.
About this breach
In April 2019, a database belonging to Lumin PDF, a cloud-based PDF editor widely used as a Google Drive add-in, was left online without a password. According to our investigation team, the breach affected roughly 24.4 million user records, with an estimated attack date of April 1, 2019. The exposure did not become public until September 2019, when the data appeared on a hacking forum.
Breach Timeline
April 2019: A MongoDB instance belonging to Lumin PDF was found exposed online without password protection. The person who found it later said they contacted the company multiple times and received no reply, according to ZDNet.
September 16, 2019: A download link to a file containing 24,386,039 Lumin PDF user records was posted on a hacking forum. ZDNet verified samples of the data and obtained comment from the company.
The person who leaked the data claimed the exposed database was later hit by MongoDB ransomware and taken offline. Lumin PDF CEO Max Ferguson confirmed to ZDNet that the leak contained a portion of user data, but disputed the claim that the leaked Google access tokens were still valid. "The leaked Google access tokens were all expired at the time of the breach, meaning that the attackers could not gain access to any user documents or signatures," Ferguson told ZDNet in an email.
What Information Was Compromised?
Our analysis found the following data types in this breach: Email addresses, Full names.
Not every individual is affected by every type of data listed here.
Contemporary reporting described additional fields in the leaked file: gender, language and locale settings, and Google access tokens for most users, most of whom used Lumin PDF as a Google Drive add-in. For 118,746 users who had registered directly on the Lumin PDF website, the file contained password strings hashed with the Bcrypt algorithm, according to ZDNet.
In a later statement, the company said the exposed database was part of its testing infrastructure and contained a mix of real and anonymized test data. It stated that no documents or files were exposed, that all leaked Google access tokens had already expired at the time of the breach, and that no access tokens from other cloud services were involved. The company also said it contacted users whose encrypted passwords were included and asked them to reset them, and that it has seen no evidence the passwords were decrypted.
What Are the Potential Risks for Affected Individuals?
The main risks from this breach involve personal information rather than documents:
Phishing. Attackers with real names and email addresses can send convincing messages that impersonate Lumin PDF, Google Drive, or document-sharing notifications.
Password reuse. If any of the roughly 118,746 bcrypt password hashes are cracked, attackers may try those passwords on other accounts where the same password was reused.
Spam and account takeover attempts. Leaked email addresses and names are commonly used for credential attacks and unwanted mail.
Token concerns. The company stated the leaked Google access tokens were expired, and Google was notified of the leak. Users who connected Lumin to Google Drive or Dropbox at the time may still want to review their connected apps.
What Is Lumin PDF Doing in Response?
Ferguson told ZDNet that the security vulnerabilities that led to the breach had been resolved and that the company planned to publish a disclosure blog post. In its later public statement, Lumin PDF said it now runs a dedicated channel for security researchers to report vulnerabilities, encrypts access tokens immediately after they are created, and worked with an external security firm to review its systems. The company also said it contacted affected users at the time of the leak.
What Should You Do If You Were Affected?
If you used Lumin PDF with a direct account, change that password, and change it anywhere else you reused it.
Review the apps connected to your Google account and revoke Lumin PDF's access if you no longer use it.
Enable two-factor authentication on your email and Google accounts.
Treat unexpected emails about PDF signatures, document permissions, or Drive access as suspicious until verified.
