Imgur, one of the world's most visited websites, has confirmed a hack dating back to 2014.
Imgur confirms email addresses, passwords stolen in 2014 hack
The hackers stole email addresses and passwords.
The company told ZDNet that hackers stole 1.7 million email addresses and passwords, scrambled with the SHA-256 algorithm, which has been passed over in recent years in favor of stronger password scramblers.
Imgur said the breach didn't include personal information because the site has "never asked" for real names, addresses, or phone numbers.
The stolen accounts represent a fraction of Imgur's 150 million monthly users.
The hack went unnoticed for four years until the stolen data was sent to Troy Hunt, who runs data breach notification service Have I Been Pwned. Hunt informed the company on Thursday, a US national holiday observing Thanksgiving, when most businesses are closed.
A day later, the company started resetting the passwords of affected accounts, and published a public disclosure alerting users of the breach.
Hunt praised the company's efforts for its quick response.
"I disclosed this incident to Imgur late in the day in the midst of the US Thanksgiving holidays," said Hunt. "That they could pick this up immediately, protect impacted accounts, notify individuals and prepare public statements in less than 24 hours is absolutely exemplary."
Imgur's chief operating officer Roy Sehgal said the company was "still investigating" how the account information was compromised, but said that site security had improved since the breach.
The company said it has changed its password hashing to bcrypt, a much stronger password scrambler, last year. But anyone who uses the same Imgur email address and password combination on other sites should also change those passwords.
Sehgal also said in an email that the company, based in California, plans to disclose the data breach to the state's attorney general, law enforcement, and other relevant government agencies.
According to Hunt, 60 percent of email addresses were already in Have I Been Pwned's database of more than 4.8 billion records.
Zack Whittaker can be reached securely on Signal and WhatsApp at 646-755–8849, and his PGP fingerprint for email is: 4D0E 92F2 E36A EC51 DAAE 5D97 CB8C 15FA EB6C EEA5.
- Leaked TSA documents reveal New York airport's wave of security lapses
- US government pushed tech firms to hand over source code
- At the US border: Discriminated, detained, searched, interrogated
- Millions of Verizon customer records exposed in security lapse
- Meet the shadowy tech brokers that deliver your data to the NSA
- Inside the global terror watchlist that secretly shadows millions
- FCC chairman voted to sell your browsing history — so we asked to see his
- With a single wiretap order, US authorities listened in on 3.3 million phone calls
- 198 million Americans hit by 'largest ever' voter records leak
- Britain has passed the 'most extreme surveillance law ever passed in a democracy'
- Microsoft says 'no known ransomware' runs on Windows 10 S — so we tried to hack it
- Leaked document reveals UK plans for wider internet surveillance