Jump directly to the content
HACK ATTACK

Imgur admits hackers stole personal email addresses and passwords from 1.7 MILLION customers

Massive data breach in 2014 was only uncovered last week

PHOTO sharing site Imgur has admitted hackers stole the email addresses and passwords of 1.7million people.

The cyber attack in 2014 was discovered only days ago by a security researcher.

 Photo sharing site Imgur has admitted a massive breach of users' data
1
Photo sharing site Imgur has admitted a massive breach of users' dataCredit: Imgur

Imgur said the hackers did not obtain other personal details such as real names or phone numbers because the site does not ask for them when people open an account.

The hack went unnoticed for nearly four years until the stolen date was sent to Troy Hunt, .

He emailed Imgur last Thursday - when most US offices were closed for Thanksgiving.

The next day Imgur began asking affected users to reset their passwords and on its website.

Troy, who runs data breach notification service Have I Been Pwned, said: "That they could pick this up immediately, protect impacted accounts, notify individuals and prepare public statements in less than 24 hours is absolutely exemplary."

The 1.7million swiped accounts are only a fraction of Imgur's 150million monthly users.

Imgur's chief operating officer Roy Sehgal said the company was "still investigating" how the account data was compromised, and added security had improved since the breach.

The login details were scrambled in the company's database with the SHA-256 algorithm, which could have been cracked. It has since been replaced with the stronger password protector Bcrypt.

Anyone who uses the same email address and password combination on other sites should change them immediately, the firm said.

Last week it was revealed Uber paid hackers £75,000 "hush money" to cover up an astonishing data breach affecting 57million customers in 2016.

In October credit ratings firm Equifax admitted more than 15million Brits were compromised in a massive cyber attack.

They included 700,000 people who had "sensitive" personal information published.

Other firms that have admitted data breaches include Disqus, LinkedIn, MySpace, and Yahoo.

Here is how you can find out if your name is on the list of hundreds of millions of compromised accounts.


We pay for your stories! Do you have a story for The Sun Online news team? Email us at tips@the-sun.co.uk or call 0207 782 4368 . We pay for videos too. Click here to upload yours.


Topics
LOGO_machibet_200x200

Machibet

star star star star star 4.9/

6,000.000+downloads/Free/Bengali/Version2.3.4

777 BDT IPL 2025 Sports First Deposit Bonus

  • 5,000 BDT Daily Reload Bonus
  • Boost Your First Deposit with a 300 BDT Bonus
  • 100% First Deposit Refund Bonus up to 5,000BDT
bKash bank OK Wallet upay
PLAY NOW
Free Bonus
Download For
android