Data breach
showme.com
- Records
- 453,565
- Breach date
- 1 January 2020Estimated
- Added
- 1 December 2024
What was exposed
2 types of data · 1 puts you at serious risk
- Email addresses453,565
- Passwords452,810
About this breach
Data tied to ShowMe.com, an online lesson-building and interactive whiteboard service, appeared in a collection of stolen records circulating on a hacking forum, according to secondary breach trackers. Our investigation team estimates the breach involved 453,565 rows of data, with an estimated attack date of January 1, 2020. No hacking group has claimed responsibility, and the exact circumstances of how the data was taken remain unclear.
Limited public reporting: As of September 25, 2026, detailed company notices or major news coverage for this listing were limited in sources reviewed. The facts below rely primarily on the indexed fields plus any secondary sources cited.
What Information Was Compromised?
Our analysis found the following data types in this breach:
Email addresses: 453,565
Passwords: 452,810
Independent breach trackers have characterized the exposed passwords as plain text, meaning they were not hashed or encrypted in the stolen records. BreachDirectory lists the incident with email addresses and plain text passwords as the compromised data classes, and Logoutify reports that the ShowMe.com data surfaced on a hacking forum as part of a collection of breach data.
Not every individual is affected by every type of data listed here.
What Are the Potential Risks for Affected Individuals?
Plain text passwords are the most serious concern in this kind of exposure. Because the passwords appear in readable form, anyone who obtains the data can try those email-and-password combinations directly on ShowMe.com and on other websites where the same credentials may have been reused.
The main risks include:
Account takeover. Attackers can log into affected accounts and access any personal content, lessons, or class materials stored there.
Credential stuffing. Automated tools can test the stolen email-and-password pairs across banking, email, social media, and shopping sites. If you used the same password elsewhere, those accounts are at risk too.
Phishing. With a verified email address and knowledge of the service you used, criminals can craft convincing messages that appear to come from ShowMe.com or related services.
Because ShowMe is used in educational settings, some affected users may be teachers or students. Attackers sometimes target such accounts to send fraudulent messages to a user's own students or contacts, adding a social engineering risk on top of the credential exposure.
What Should You Do If You Were Affected?
Even without a confirmed company notice, there are practical steps you can take:
Change your ShowMe.com password immediately. If you still use the account, set a new, unique password. If you no longer use it, consider deleting or deactivating the account.
Change that password anywhere else you reused it. Password reuse is what turns a single-site breach into a multi-site problem. Each important account, especially email and banking, should have its own password.
Use a password manager. It generates and stores strong, unique passwords so you do not have to remember them.
Turn on two-factor authentication wherever the service offers it. This blocks most account takeover attempts even if a password is known.
Watch for phishing. Be cautious with emails referencing ShowMe.com, password resets, or account problems. Do not click links in unsolicited messages; go to the site directly instead.
Monitor your accounts for unfamiliar logins or activity, and check whether your email address appears in this or other breaches.
