Comments leaked: what it means and what to do

Risk level: low. Can you change it: no. Found in 1 breaches in this directory.

What this data is

Remarks you left under articles, videos, products or posts, stored with your username and date, and often with the email address and IP address behind the account.

The risk on its own

Most comments were public when you wrote them, so the content itself is rarely new. What the breach usually adds is the hidden part: the email address and IP address behind a username. That is what connects an anonymous commenter to a real person.

The risk combined with other data

Once comments are joined to your real email they can be searched for anything that embarrasses you or reveals views you kept apart from your name. Old remarks made in a different context can be used to damage your reputation or pressure you at work. For people who comment under a pseudonym for their own safety, the link itself is the harm.

How criminals use it

  • Someone digs up years-old comments made under a pseudonym and sends them to your employer.
  • A harasser uses the email behind your username to find your other accounts and your real name.
  • Comments on sensitive topics, such as a health condition or a political issue, are used to profile or out you.

What to do now

  1. Log in to the site and delete old comments you would not want tied to your name, then close the account if you no longer use it.
  2. Change the password if you used it anywhere else, since comment platforms are often poorly secured.
  3. Use a separate email address or alias for accounts where you post under a pseudonym.
  4. Search your old usernames in a search engine to see which other posts they connect you to.

Frequently asked questions

My comments were public anyway. What changed?

The breach links them to the private email address or IP address behind your username, which can reveal who wrote them.

Can I get old comments removed?

You can delete them from the live site and ask the company to erase your account. Copies in the leak and in web archives may remain.

Is this a security risk?

Mostly a reputation and privacy risk. The security part of the breach is the password and email address.

Breaches that exposed this data

  • BitView: 2024-12-14, 63K accounts, Bios, Comments, Dates of birth, Email addresses, Genders, Geographic locations

Tools that help

Related guides

Breach data sourced from Have I Been Pwned, used under CC BY 4.0. Additional breach metadata provided by XposedOrNot. DataExposed is an independent service and is not affiliated with or endorsed by either.