Breach report
Social MediaTumblr (Yahoo)
Hackers Stole 65 Million Passwords From Tumblr, New Analysis Reveals
A 2013 intrusion at Tumblr exposed more than 65 million email addresses and hashed passwords. The company disclosed it vaguely in 2016, and outside researchers revealed the true scale weeks later.
Reported by Vice (Motherboard)
Records exposed
65.5M
65,469,298 accounts
Scale vs. largest on file
- When
- 2013 (disclosed 2016)
- How they got in
- Database theft
- Sector
- Social Media
On May 12, 2016, Tumblr posted a brief notice saying it had recently learned that a third party had obtained a set of user email addresses and passwords dating back to early 2013, before the blogging platform was acquired by Yahoo for about $1.1 billion. The company did not say how many accounts were involved, and it asked affected users to change their passwords.
The missing number emerged about two weeks later. Security researcher Troy Hunt, who runs the breach-notification service Have I Been Pwned, obtained a copy of the data and found 65,469,298 unique email addresses paired with password hashes. At the time that made it one of the three largest known credential breaches, behind LinkedIn and Adobe. The dataset was being offered for sale on a dark web market by Peace, the same seller behind the LinkedIn, Myspace and VK dumps, for a relatively low price.
Unlike some of its contemporaries, Tumblr had at least salted its SHA-1 password hashes, which slows down cracking considerably because each hash must be attacked individually. That likely explains why the data sold cheaply. Even so, experts warned that SHA-1 was a fast algorithm poorly suited to password storage, that the age of the dataset made cracking more feasible over time, and that weak or common passwords would still fall quickly.
The incident drew criticism over transparency. Tumblr's decision to disclose without specifying scale left users unsure whether to act, and the size became known only through independent analysis. The breach also foreshadowed much larger problems at its parent company: later in 2016 Yahoo revealed that attacks in 2013 and 2014 had compromised all of its roughly three billion user accounts, disclosures that shaved hundreds of millions of dollars off Verizon's acquisition price for Yahoo.
The Tumblr case is a useful lesson in both engineering and communication. Salting helped, but modern password storage calls for deliberately slow algorithms such as bcrypt, scrypt or Argon2. And a breach notice that omits the number of affected users tends to erode trust rather than protect it, especially when independent researchers are likely to publish the figure anyway.