Data breach
Zoosk
- Records
- 53,780,991
- Breach date
- 1 January 2011Estimated
- Added
- 1 December 2024
What was exposed
2 types of data · 1 puts you at serious risk
- Email addresses53,780,991
- Passwords53,777,314
About this breach
In or around 2011, a large dataset circulating online was attributed to the dating website Zoosk, containing tens of millions of records with email addresses and passwords. The investigation team indexes the listing at 53,780,991 rows and estimates the breach date as January 1, 2011. However, this incident carries a significant caveat: independent verification efforts have found no evidence that the data actually came from Zoosk, and the breach remains unverified. Readers should treat the attribution to Zoosk as disputed rather than confirmed.
May 2016: An extensive verification effort found no evidence that the circulating records were sourced from Zoosk, and the dataset was flagged as likely fabricated, according to Leaked.Domains.
February 8, 2017: The Zoosk incident was added to Mozilla Monitor's breach database, which lists email addresses and passwords as the compromised data types, according to Mozilla Monitor.
What Information Was Compromised?
Our analysis found the following data types in this breach: email addresses (53,780,991 records) and passwords (53,777,314 records).
Given the disputed origin of the data, it is unclear whether these records were ever tied to genuine Zoosk accounts. External compilations describe the password material inconsistently, with some listing it as plaintext and others as hashed, so the true state of the password data cannot be confirmed from available sources.
Not every individual is affected by every type of data listed here.
What Are the Potential Risks for Affected Individuals?
If your email address appears in this dataset, the most immediate risk is credential-based attack. Attackers routinely test email and password pairs from leaked lists against other websites, a technique known as credential stuffing. If you reused the password from this period on other accounts, those accounts could be vulnerable.
The dating-site context adds a second risk: phishing. People who once used dating services are common targets for fake account-verification messages, romance scams, and emails that reference a breach to pressure recipients into clicking malicious links. Even if this dataset is fabricated, a list this large can still fuel mass phishing campaigns, because email addresses remain valid attack targets regardless of whether the passwords are real.
There is also a limit to the harm here. Because the data's link to Zoosk was never verified, it may not reflect any actual exposure of Zoosk accounts. The practical risk depends on whether the email and password combinations match credentials you used in 2011, not on whether Zoosk itself was hacked.
What Should You Do If You Were Affected?
If you had a Zoosk account, or simply want to be cautious, take these steps:
Change your password on Zoosk if you still have an account, and change it anywhere else you reused it. Passwords from the 2011 era are especially likely to have been reused across sites.
Use a unique, strong password for each account. A password manager can generate and store them for you.
Turn on two-factor authentication wherever it is offered, starting with your primary email account, which protects access to nearly everything else.
Be skeptical of emails referencing Zoosk, dating profiles, or a data breach. Do not click links or open attachments in unexpected messages, and go directly to a site's official address instead.
Watch your accounts for signs of unauthorized access, such as unfamiliar login alerts or password-reset emails you did not request.
Because the breach itself is unverified, checking whether your email appears in this dataset is the most reliable way to assess your personal exposure.
