Data breach
Netlog
- Records
- 55,981,455
- Breach date
- 1 November 2012Estimated
- Added
- 3 January 2025
What was exposed
2 types of data · 1 puts you at serious risk
- Email addresses55,981,455
- Passwords55,892,499
About this breach
Netlog, a Belgian social networking platform operated by Massive Media, suffered a database compromise in November 2012 that exposed the email addresses and passwords of tens of millions of registered users. According to our investigation team, the breach involves roughly 56 million records, including about 55.9 million passwords and about 56 million email addresses. The company itself did not learn of the incident until years later, when its security team discovered it through proactive data security monitoring. Netlog shut down in 2015, and its operator, which also ran the dating platform Twoo, notified affected users and regulators only after the discovery.
Limited public reporting: As of September 25, 2026, detailed company notices or major news coverage for this listing were limited in sources reviewed. The facts below rely primarily on the indexed fields plus any secondary sources cited.
Breach Timeline
November 2012: A database compromise at Netlog exposed user email addresses and passwords, according to a company notice filed with the California Attorney General.
July 2018: The breach was reported to authorities, according to DutchITchannel, which also reported that the company had put the number of affected accounts at about 16.4 million.
What Information Was Compromised?
Our analysis found the following data types in this breach: email addresses and passwords.
The company notice states the compromised database covered users who registered for Netlog before December 2012 and that it contained email address and password information. The notice also confirms the database did not contain government issued identification numbers, payment card details, or banking information, and that the company had no reason to believe any other data or service was compromised.
Not every individual is affected by every type of data listed here.
What Are the Potential Risks for Affected Individuals?
Because the breach exposes email and password combinations, the main risk is password reuse. Anyone who used the same email address and password combination on Netlog and on other accounts, such as email providers, banking sites, or social media, is vulnerable to account takeover on those services. Attackers commonly test leaked credentials against many popular websites, a technique known as credential stuffing.
Exposed email addresses can also fuel phishing. Criminals may send convincing messages that reference the breach or impersonate services the recipient uses, hoping to trick people into revealing more credentials or personal details. Because the breach happened in 2012 and resurfaced in 2018, any affected passwords may already be circulating widely, and risks can persist long after the original incident.
What Is Netlog Doing in Response?
According to the company notice, Netlog's security team discovered the compromise through proactive data security monitoring. As part of its response, the company notified all known affected Netlog users, as well as authorities as required by law. The notice directs people with questions to contact security@netlog.com. Because the Netlog service was discontinued in 2015 and is not operational, the company says there is nothing for users to do on Netlog itself. We did not find additional public statements about the incident in sources reviewed as of September 25, 2026.
What Should You Do If You Were Affected?
If you had a Netlog account before December 2012, treat the email address and password you used then as compromised, even if you have not received a notice.
Change your password anywhere you still use the same combination, starting with email and financial accounts.
Use a unique password for every account. Avoid personal information and common words, mix letters, numbers, and symbols, and make passwords at least 8 characters long.
Turn on two factor authentication wherever it is offered.
Watch for phishing emails that mention Netlog, Twoo, or the breach, and do not click links or enter credentials in unexpected messages.
