Breach report
Social MediaQuora
100 Million Quora Users Affected By 'Malicious' Data Breach
Question-and-answer site Quora disclosed in December 2018 that a malicious third party had accessed data on about 100 million users, including names, emails, hashed passwords and some private messages.
Reported by NPR
Records exposed
100M
About 100 million users
Scale vs. largest on file
- When
- 2018
- How they got in
- Unauthorized access to company systems by a malicious third party
- Sector
- Social Media
On December 3, 2018, Quora said it had discovered that a malicious third party had gained unauthorized access to one of its systems, compromising information on approximately 100 million users. The question-and-answer platform said it had learned of the intrusion the previous Friday, November 30, and moved quickly to notify users. Chief executive Adam D'Angelo published a post explaining the incident and apologizing.
The exposed account information included names, email addresses, encrypted, or hashed, passwords, and data imported from linked networks such as Facebook and Twitter when users had authorized it. Public content, including questions, answers, comments and upvotes, was also accessed, as was some non-public content: answer requests, downvotes, and direct messages between users. Quora said a relatively low percentage of users had sent or received such messages. Questions and answers posted anonymously were not affected, because the company did not store the identities of anonymous authors.
Quora did not describe exactly how the attacker got in, saying only that the investigation was ongoing with a leading digital forensics and security firm and that law enforcement had been notified. As a precaution, the company logged out all affected users and invalidated passwords for those who used them to sign in, requiring resets.
The breach landed during a bruising stretch for data security. Days earlier, Marriott had disclosed that its Starwood guest reservation database had been exposed, affecting up to 500 million customers, and the year had also brought major incidents at Facebook and Google+. Quora faced criticism from privacy advocates, but no significant regulatory penalty was announced. The company, a private startup, did not report any financial fallout from the incident.
The Quora breach highlighted how platforms built on user-generated content hold more than just login credentials. Private messages and behavioral signals such as downvotes and answer requests can reveal a great deal about a person's interests and relationships. It also showed the reach of social login integrations, since data imported from other networks was exposed alongside Quora's own records. For users, it underscored the value of unique passwords and of reviewing which third-party apps are connected to social media accounts.