Data breach
YouNow
- Records
- 35,268,736
- Breach date
- 15 February 2019Estimated
- Added
- 1 December 2024
What was exposed
8 types of data
- Usernames34,680,327
- Names33,710,786
- IP addresses27,136,894
- Email addresses19,303,271
- Facebook profiles12,343,477
- Google accounts11,641,650
- Instagram profiles3,231,780
- X / Twitter profiles1,759,989
About this breach
In February 2019, a database containing tens of millions of user records from YouNow, a live-streaming platform popular with younger audiences, surfaced for sale on a dark web marketplace. The listing contains 35,268,736 rows of user data tied to younow.com. No passwords were included in the exposed data, according to Mozilla Monitor, which tracks known data breaches and lists this incident. No hacking group has publicly claimed responsibility, and the listing is unclaimed in the records.
Limited public reporting: As of September 25, 2026, detailed company notices or major news coverage for this listing were limited in sources reviewed. The facts below rely primarily on the indexed fields plus any secondary sources cited.
What Information Was Compromised?
Our analysis found the following data types in this breach:
Usernames or nicknames, present in 34,680,327 records
Names, present in 33,710,786 records
IP addresses, present in 27,136,894 records
Email addresses, present in 19,303,271 records
Facebook profile identifiers, present in 12,343,477 records
Google account identifiers, present in 11,641,650 records
Instagram profile identifiers, present in 3,231,780 records
Twitter profile identifiers, present in 1,759,989 records
Not every individual is affected by every type of data listed here.
The records combined account details with links to users' social media profiles, meaning a person's YouNow presence could be connected to their Facebook, Instagram, Twitter, or Google accounts. Many records lacked an email address, which is why the email count is lower than the total number of rows. Notably, the data did not include passwords or payment information.
What Are the Potential Risks for Affected Individuals?
Because no passwords were exposed, the direct risk of account takeover through this breach alone is low. The greater risks come from how the other data can be used. Names paired with email addresses and social media profile links give scammers the raw material for convincing phishing messages, impersonation attempts, and targeted social engineering. Someone posing as a friend or follower on another platform is more believable when they know your real name and accounts.
IP addresses can reveal a person's approximate location and internet provider, which adds credibility to fraudulent messages and can be used for doxxing. The links between YouNow accounts and personal social media profiles also make it easier for stalkers or harassers to build a fuller picture of an individual, a concern for a platform whose user base skews young.
What Should You Do If You Were Affected?
If you used YouNow, there are practical steps you can take, even without any password exposure:
Treat unexpected emails, direct messages, or friend requests that reference YouNow or your streaming activity with suspicion, and never click links or share codes sent by people you cannot verify.
Check whether your email address appears in this breach using the search tool.
Review the privacy settings on your Facebook, Instagram, Twitter, and Google accounts, since this data links those profiles to YouNow identities.
Use unique, strong passwords for every account and store them in a password manager, which limits the damage if any of your accounts are targeted later.
Consider enabling two-factor authentication on your email and social media accounts to block takeover attempts.
Be alert to impersonation, since your name and social profiles are now in circulation among people who trade in stolen data.
