Data breach
todotorrents.com
- Records
- 522,449
- Breach date
- 1 January 2020Estimated
- Added
- 1 December 2024
What was exposed
2 types of data · 1 puts you at serious risk
- Email addresses522,449
- Passwords520,934
About this breach
The torrent download site TodoTorrents.com has appeared in a leaked database containing records for roughly half a million user accounts. The dataset tied to todotorrents.com holds 522,449 rows, including 522,449 email addresses and 520,934 passwords. The team estimates the breach occurred around January 1, 2020, though the listing was not indexed until December 1, 2024. No individual or group has claimed responsibility, and the site's operator has not published a notice about the incident in the sources reviewed.
Limited public reporting: As of September 25, 2026, detailed company notices or major news coverage for this listing were limited in sources reviewed. The facts below rely primarily on the indexed fields plus any secondary sources cited.
Independent breach search services corroborate the core facts. LeakCheck reports it has indexed about 521,000 records from the TodoTorrents.com breach, consisting of email addresses and passwords. Another breach index, Logoutify, describes the TodoTorrents.com data as having surfaced on a hacking forum as part of a collection of breaches, and lists the compromised data as email addresses and plain text passwords. Plain text passwords, if accurate, would mean credentials were stored without proper hashing, which makes the leak more directly usable by attackers.
TodoTorrents, accessible at todotorrents.org, is a Spanish-language site that hosts links to torrent files for films and television series. Because the site's operator has not publicly addressed the leak, it remains unclear how the database was obtained or how long it circulated before being indexed.
What Information Was Compromised?
Our analysis found the following data types in this breach: email addresses and passwords.
Not every individual is affected by every type of data listed here.
Nearly every record in the dataset contains an email address. The password count, 520,934, falls slightly short of the total row count, which means some records lack a password field. No names, payment details, or other identity documents are listed in the indexed data.
What Are the Potential Risks for Affected Individuals?
The main risk from an email and password leak is credential reuse. Many people use the same password across multiple accounts, including email, banking, and social media. Attackers take leaked credential pairs and try them automatically against hundreds of other services, a technique known as credential stuffing. An account that shares a password with TodoTorrents is a candidate for this kind of takeover.
Even where the leaked passwords are hashed rather than plain text, weak or common passwords can be cracked in bulk. Successful account takeovers can lead to further problems: password reset emails intercepted at a compromised inbox, fraudulent purchases, identity phishing aimed at friends and contacts, and attempts to extort victims with emails that quote the leaked password to appear credible.
Because the data has circulated on hacking forums, it may already be in the hands of many different actors, and the risk does not fade quickly after a leak is published.
What Should You Do If You Were Affected?
If you had an account on TodoTorrents, take these steps:
Change your TodoTorrents password immediately, and change it anywhere else you used the same or a similar password.
Use a unique password for every account. A password manager makes this practical.
Turn on two-factor authentication wherever the service offers it, starting with your email account.
Watch for phishing emails that reference the site, torrenting, or that quote an old password to lend credibility. Do not click links in unsolicited messages.
Check whether your email address appears in this breach using the search tool, and review other accounts tied to the same address.
