Data breach
Tianya
- Records
- 31,183,556
- Breach date
- 26 December 2011Estimated
- Added
- 1 December 2024
What was exposed
3 types of data · 1 puts you at serious risk
- Email addresses31,183,556
- Usernames31,183,521
- Passwords31,156,737
About this breach
In late December 2011, Tianya, one of China's largest and best-known online forums, confirmed that a database containing tens of millions of user records had leaked online. According to our investigation team, the indexed dataset contains more than 31.18 million records, most of them accompanied by passwords, with an estimated attack date of December 26, 2011. The leak landed during a wave of breaches at Chinese websites that month, and it followed a similar disclosure by the developer community site CSDN days earlier. Chinese media reported that a large file containing Tianya usernames, passwords, and email addresses circulated widely, and users who tested their own IDs against an online lookup tool found their account details returned correctly.
Breach Timeline
December 21, 2011: Reporting on the leak wave began after CSDN disclosed a breach affecting more than 6 million user records with plaintext passwords, according to Caixin.
December 25, 2011: A file containing Tianya user data, reported by media at the time to cover roughly 40 million accounts, spread online, and Tianya posted an apology and a statement on its homepage, per China News Service.
December 28, 2011: China's Ministry of Industry and Information Technology said it had activated an emergency response plan as the leak wave widened, according to a Hunan government industry department retrospective.
January 10, 2012: A government notice confirmed that Tianya was among the few sites where a real breach had occurred, attributing the intrusion to a hacker compromise before 2009, per the same retrospective.
What Information Was Compromised?
Our analysis found the following data types in this breach: usernames or nicknames, 31,183,521 records; passwords, 31,156,737 records; and email addresses, 31,183,556 records.
Contemporary reporting and Tianya's own statement indicate the leaked passwords had been stored in plaintext, a consequence the company attributed to its early account systems. Tianya said the stolen data was a backup from before 2009 and that stronger encryption had been introduced later, though some users questioned why accounts registered after that period also appeared in the leak.
Not every individual is affected by every type of data listed here.
What Are the Potential Risks for Affected Individuals?
Because the passwords were stored in plaintext, anyone who obtained the file could read them directly. The main risks follow from that:
Account takeover. Anyone still using the same password on Tianya, or on any other site, could have those accounts accessed by attackers.
Credential stuffing. Attackers routinely replay leaked email and password pairs against other services, since many people reuse passwords across sites.
Phishing. With real email addresses tied to a known service, affected users are plausible targets for messages that impersonate Tianya or other websites and ask for credentials or personal details.
Identity exposure. Username and email combinations tied to a person's forum activity can aid targeted scams or further research into an individual.
What Is Tianya Doing in Response?
Tianya posted an apology letter and a formal statement on its homepage asking users to change their Tianya passwords immediately and to update the same password anywhere else it was used. The company said it had reported the matter to the police, that the leaked material was a pre-2009 backup, and that its account management system had since been upgraded with strong encryption. Customer service lines reported a surge in calls about the leak, and company executives said Tianya would cooperate with investigators, according to Sina Tech.
What Should You Do If You Were Affected?
Change your Tianya password if the account still exists, and change any other account that used the same or a similar password.
Use a unique, strong password for every service, ideally generated and stored by a password manager.
Turn on two-factor authentication wherever a site or app offers it.
Be cautious with emails or messages claiming to be from Tianya or other forums asking you to log in or verify details; go to the site directly instead of clicking links.
Watch for unusual activity on email accounts tied to the old registration, since those addresses are in the leak.
