Data breach
ShareThis
- Records
- 41,027,448
- Breach date
- 9 July 2018Estimated
- Added
- 1 December 2024
What was exposed
4 types of data · 2 more reported · 1 puts you at serious risk
- Usernames41,027,441
- Email addresses41,017,584
- Names39,860,790
- Passwords1,899,474
- GenderReported, not counted
- Dates of birthReported, not counted
Reported in the breach write-up; not counted in the analysed data.
About this breach
In July 2018, ShareThis, the Palo Alto-based company behind a widely used social sharing widget, lost a database containing tens of millions of user accounts to an unknown attacker. The theft went unnoticed for months. It only became public in February 2019, when a seller offered the database, alongside data from 15 other companies, for sale on a dark web marketplace, and The Register reported on the listing. ShareThis, which was not previously aware of the incident, then launched an investigation and began notifying affected users. Our investigation team's index contains 41,027,448 records from this breach, including more than 41 million email addresses and nearly 40 million names.
Breach Timeline
July 2018: ShareThis believes the unauthorized access to its cloud-hosted database occurred during this month, based on its own investigation, which our team's estimated breach date of July 9, 2018 matches.
February 11, 2019: According to a notice ShareThis filed with the California Attorney General, the company became aware of the incident after The Register published a story about user databases from 16 companies being offered for sale on the dark web.
February 28, 2019: ShareThis began sending written notification letters to affected individuals, including California residents.
What Information Was Compromised?
Our analysis found the following data types in this breach: usernames (nicknames), email addresses, names, and passwords. The indexed records include 41,017,584 email addresses, 39,860,790 names, 41,027,441 usernames, and 1,899,474 password entries.
Reporting by The Register described the stolen ShareThis records as containing names, usernames, email addresses, DES-hashed passwords, gender, dates of birth, and other profile information. ShareThis's own notice to the California Attorney General stated that names, email addresses, hashed passwords, and some birth dates could have been subject to unauthorized access.
The password hashing matters here. DES-based password hashing is an outdated and weak method, and security reporting at the time noted that these hashes could plausibly be cracked. Because the database did not include address information, ShareThis stated it did not know where potentially affected individuals lived.
Not every individual is affected by every type of data listed here.
What Are the Potential Risks for Affected Individuals?
The main risk is account takeover. If a weakly hashed password is cracked, an attacker can try the same email and password combination on other websites, a tactic known as credential stuffing. Many people reuse passwords, so a ShareThis credential can unlock email, banking, or social media accounts elsewhere.
Email addresses and names are also useful for phishing. Someone holding this database can send convincing fake security notices or password reset emails that appear to come from a service the recipient actually used. Dates of birth and gender, where present, can help attackers answer security questions or build more believable scams.
ShareThis stated in its notice that it had no indication any of the potentially affected information had been used by the attacker or anyone else, but the data was offered for sale publicly, meaning anyone could have bought a copy.
What Should You Do If You Were Affected?
Change your password anywhere you reused the one you used on ShareThis, starting with your email and financial accounts. ShareThis deactivated breached accounts, so logins required a reset.
Use long, unique passwords for each account, ideally stored in a password manager.
Turn on two-factor authentication wherever it is offered.
Be skeptical of unexpected emails about account security, and go directly to a website rather than clicking links in such messages.
Watch your financial accounts and credit reports for unexplained activity.
If you have questions about the incident, ShareThis's notice directed people to email inquiries@sharethis.com.
In the news
- The Register: 620 million accounts stolen from 16 hacked websites now for sale on dark webtheregister.com (opens in a new tab)
- ShareThis Notice of Data Event, California Attorney Generaloag.ca.gov (opens in a new tab)
- ZDNet: 127 million user records from 8 companies put up for sale on the dark webzdnet.com (opens in a new tab)
- IDStrong: Data from ShareThis.com Breach Appeared on Dark Webidstrong.com (opens in a new tab)
