Data breach
Xiaomi
- Records
- 1,034,125
- Breach date
- 1 August 2012Estimated
- Added
- 24 July 2026
What was exposed
1 type of data · 3 more reported
- Email addresses1
- PasswordsReported, not counted
- UsernamesReported, not counted
- IP addressesReported, not counted
Reported in the breach write-up; not counted in the analysed data.
About this breach
The Xiaomi forum data breach stems from a security weakness in the account system the Chinese phone maker used before August 2012. The investigation team has indexed 1,034,125 records tied to this listing, with an estimated breach date of August 1, 2012. The leak itself became public in May 2014, when the Chinese vulnerability disclosure platform Wooyun reported that Xiaomi's forum user database was circulating on cloud storage services. Chinese media, citing Wooyun, put the number of affected users at roughly 8 million; Xiaomi acknowledged that some forum account information registered before August 2012 had been illegally obtained, though it said only a small share of accounts remained at risk because many users had already changed their passwords. No hacking group has claimed responsibility for the breach, according to the records.
Limited public reporting: As of September 25, 2026, detailed company notices or major news coverage for this listing were limited in sources reviewed. The facts below rely primarily on the indexed fields plus any secondary sources cited.
May 13, 2014: Wooyun, a Chinese vulnerability reporting platform, disclosed that Xiaomi's forum user database had leaked and was spreading on cloud storage services, affecting an estimated 8 million users.
May 14, 2014: Xiaomi posted a security notice on its community forum confirming that some forum account information for users registered before August 2012 had been illegally obtained, and said it would notify affected users by text message and email to reset their passwords.
What Information Was Compromised?
Our analysis found the following data types in this breach: email addresses.
Wooyun's disclosure, as reported by Chinese outlets including Xinhua's Economic Reference outlet, described the leaked forum database as containing usernames, passwords, registration email addresses, registration IP addresses, and password salts. The passwords were not stored in plain text; Xiaomi said they were protected with individually salted one-way hashes. Security analysts cited by Guancha estimated that 70 to 80 percent of the hashed passwords could still be recovered, with simple passwords the easiest to crack.
Not every individual is affected by every type of data listed here.
What Are the Potential Risks for Affected Individuals?
The most immediate risk is account takeover. Anyone who reused the same password on other services could see those accounts compromised through credential stuffing, where attackers test leaked email and password pairs on other websites.
Chinese reporting at the time also described a second wave of harm: users reported harassing phone calls in which callers knew their names, addresses, phone numbers, and purchase records, using the details for scams involving cash-on-delivery product pitches. Stolen email addresses and usernames also support targeted phishing, in which criminals pose as a legitimate company to trick people into handing over more information.
What Is Xiaomi Doing in Response?
Xiaomi confirmed the leak through its security center and published a notice titled "Account Security Prevention Announcement" pinned to its community forum, according to People's Daily Online. The company said accounts registered after August 2012 were unaffected because it had retired its older forum account system, which was built on third-party open-source software, and moved all services to a new account security framework at that time.
Xiaomi said it would prompt users registered before August 2012 who had not changed their passwords since then to do so, require immediate password resets for the small share of accounts still considered at risk, and add features such as alerts for logins from unfamiliar locations.
What Should You Do If You Were Affected?
If you had a Xiaomi forum account registered before August 2012, or you simply want to be safe:
Change your Xiaomi password immediately, if you have not since 2012, and choose a long, unique password.
Change that password anywhere else you reused it, especially email and banking accounts.
Be skeptical of unsolicited calls or emails that reference your name, address, or purchase history; do not confirm personal details or make payments to unexpected callers.
Turn on two-factor authentication wherever the service offers it.
In the news
- Guancha: Report on the Xiaomi forum data leak and Xiaomi's responseguancha.cn (opens in a new tab)
- People's Daily Online: Xiaomi confirms 8 million users affectedtc.people.com.cn (opens in a new tab)
- Xinhua Economic Reference: Wooyun discloses leaked Xiaomi database fieldsjjckb.xinhuanet.com (opens in a new tab)
- China Securities Journal: Xiaomi confirms leak, urges password changescs.com.cn (opens in a new tab)
