HackingStolen CredentialsBrute ForceDelayed DiscoveryCREDENTIALSPIILowContained
Imgur
bd_00752b9c7d105e20 · schema v1 · pii pii-v1
Full breach record for Imgur →Imgur disclosed a 2014 data breach in a 2017 notification. An unauthorized third party stole user account data (email and password). Passwords were cracked via brute force using an older SHA-256 hashing algorithm. Imgur required password resets and updated to Bcrypt. No specific affected individual count was provided in the filing.
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-113864
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Nov 24, 2017
- Raw hash
- 448299351a2aeec3cd19c0de3b09518e7c94c536d5534345e32bab8e44fcaa58
Reporting entity
- Name
- Imgurnorm: imgur
Victim entity
- Name
- Imgurnorm: imgur
Incident
- Discovered
- Nov 23, 2017
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- CREDENTIALSPII
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1110 Brute ForceT1078 Valid Accounts
- Threat actor
- ExternalFinancial
- Initial access
- valid_credentials
Compliance
- Time to disclose
- ≤1 day(1 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.