Data breach
Petflow
- Records
- 1,230,665
- Breach date
- 9 December 2017Estimated
- Added
- 1 December 2024
What was exposed
2 types of data · 1 puts you at serious risk
- Email addresses1,230,665
- Passwords1,230,659
About this breach
PetFlow, an online pet food delivery service, was the source of a data breach affecting roughly 1.2 million user accounts, according to our investigation team. The breach is estimated to have occurred on December 9, 2017, but it did not come to light until early 2019, when a seller known as "gnosticplayers" put a batch of stolen account data up for sale on the dark web marketplace Dream Market. BleepingComputer reported that the PetFlow listing contained 1.5 million entries, described as email addresses, usernames, and password hashes. The listing was part of a larger sale involving 127 million records taken from eight companies.
When asked about the listing, PetFlow denied any breach. In a comment to BleepingComputer, the company said, "To our knowledge, we've never been breached. Our information is secure and has not been hacked." No breach notification from the company has been publicly identified as of September 25, 2026.
Breach Timeline
December 9, 2017: Mozilla Monitor dates the PetFlow breach to this day, citing email addresses and passwords as the compromised data.
February 14, 2019: BleepingComputer reports that a 127-million-record batch, including 1.5 million PetFlow entries, was listed for sale on Dream Market by the seller "gnosticplayers."
February 15, 2019: PetFlow tells BleepingComputer it has no knowledge of ever being breached.
May 26, 2020: The breach is verified and added to Mozilla Monitor's public breach database.
What Information Was Compromised?
Our analysis found the following data types in this breach: email addresses (1,230,665) and passwords (1,230,659). The seller's dark web listing, as reported by BleepingComputer, also described usernames and password hashes alongside the email addresses.
Not every individual is affected by every type of data listed here.
What Are the Potential Risks for Affected Individuals?
The main risk from a password-and-email breach is account takeover. Criminals routinely test stolen email and password pairs against other websites, a technique called credential stuffing, because many people reuse the same password across multiple services. If you used your PetFlow password elsewhere, those accounts could be at risk.
Stolen email addresses are also useful for phishing. Attackers who know a real email address and a site you used can craft convincing messages that appear to come from familiar services, luring recipients to fake login pages or malicious links. Anyone whose data appears in this breach should treat unexpected emails asking for credentials or payment details with suspicion.
What Is Petflow Doing in Response?
Publicly, PetFlow has disputed the breach. In February 2019, the company told BleepingComputer that, to its knowledge, it had never been breached and that its information had not been hacked. Our investigation team could not find a public breach notification from PetFlow or an independent confirmation from the company as of September 25, 2026.
What Should You Do If You Were Affected?
If you had a PetFlow account, take the following steps:
Change your PetFlow password immediately, and change it anywhere else the same password was used.
Use a unique password for every account. A passphrase combining several unrelated words, with numbers and symbols, is a good approach.
Turn on two-factor authentication wherever it is offered, especially for email and financial accounts.
Watch for phishing. Be cautious with emails referencing PetFlow or asking you to log in, reset passwords, or confirm payment details.
Check whether your email appears in this breach.
