Data breach
renren.com
- Records
- 4,720,504
- Breach date
- 1 January 2011Estimated
- Added
- 4 March 2025
What was exposed
2 types of data · 1 puts you at serious risk
- Email addresses4,720,504
- Passwords3,275,664
About this breach
In December 2011, Renren, one of China's largest social networking platforms at the time, was caught up in a wave of leaks that exposed user account information from dozens of Chinese websites. According to our investigation team, the renren.com listing contains 4,720,504 records, including email addresses for all of them and passwords for 3,275,664 accounts. The leak surfaced amid a broader cascade of disclosures that month, when databases from sites including CSDN, Tianya and Duwan appeared online, many with passwords stored in plain text.
December 2011: Files described as containing millions of Renren user records began circulating online, alongside leaked databases from CSDN and other Chinese websites.
December 22, 2011: Renren issued a statement through its official microblog account recommending that users immediately change their password if it matched passwords used on CSDN or other recently breached sites. According to Marbridge Consulting, the company said at the time that it could not confirm its users' information had actually been leaked, and that the warning was issued only out of security considerations.
What Information Was Compromised?
Our analysis found the following data types in this breach: email addresses for 4,720,504 accounts and passwords for 3,275,664 of them. Independent security reporting on the incident has described the December 2011 Renren leak as involving roughly 4.7 million user records.
Not every individual is affected by every type of data listed here.
What Are the Potential Risks for Affected Individuals?
The main risk is password reuse. In the same December 2011 leak wave, passwords from CSDN and Tianya were exposed in plain text, and many people used the same password across multiple Chinese websites. Anyone who reused a Renren password elsewhere could have had those accounts opened by attackers working from the leaked lists.
Email addresses paired with passwords also enable phishing. Attackers can send messages that appear to come from Renren or other services, referencing real account details to pressure recipients into handing over more information. And because the data has circulated for well over a decade, it remains a resource for anyone running automated credential-stuffing attacks against modern sites.
What Is renren.com Doing in Response?
According to Marbridge Consulting's December 2011 report, Renren notified users said to be affected with instructions on how to change their passwords, and used its official microblog to urge users to change shared passwords. The company stopped short of confirming that a leak had occurred. No verified public statement from Renren addressing this incident beyond that period was found in research for this article as of September 25, 2026.
What Should You Do If You Were Affected?
Change your Renren password if you still have an account, and change it anywhere else you used the same one.
Watch for phishing emails that reference your Renren account or the 2011 leak. Attackers sometimes use old breach data to make scams look legitimate.
Use a unique password for each account, ideally generated and stored by a password manager.
Enable two-factor authentication where services offer it, so a leaked password alone is not enough to break in.
