Breach date: 2020-10-03. Added to this index: 2021-12-05. Accounts affected: about 114M. Domain: gravatar.com.
In October 2020, a security researcher published a technique for scraping large volumes of data from Gravatar, the service for providing globally unique avatars . 167 million names, usernames and MD5 hashes of email addresses used to reference users' avatars were subsequently scraped and distributed within the hacking community. 114 million of the MD5 hashes were cracked and distributed alongside the source hash, thus disclosing the original email address and accompanying data. Following the impacted email addresses being searchable in HIBP, Gravatar release an FAQ detailing the incident.
Breach data sourced from Have I Been Pwned, used under CC BY 4.0. Additional breach metadata provided by XposedOrNot. DataExposed is an independent service and is not affiliated with or endorsed by either.
The Gravatar breach exposed Email addresses, Names, Usernames. About 114M accounts were affected.
Run the free email breach check with the address you used on that service. It will tell you whether your address appears in this dataset.
Treat any message that quotes details from this breach as suspicious, turn on two-factor authentication, and consider removing your details from people-search sites if your address or phone was included.