500px Hacked – Attackers Stolen 14.8 Million Users Personal Data

500px , an online photography community suffering a massive data breach that leaked 14.8 million users personal information by cybercriminals.

500px global network for photographers and the platform managing around 16 million users who get paid for their work and skills.

Security experts learned this security incident in July 2018 when an
unauthorized party breaking the 500px systems and gained access to users personal information.

In this case, Intruder accessed the user’s sensitive information including
first and last name, username, email address, hashed password, Date of birth, city, state/province, country, and gender.

500px Engineering team already deployed to mitigate this incidents and the company believes that there is no indication of unauthorized access” to user accounts, adding that information like credit card numbers since these data aren’t saved on company server.

The company said that users who have opt-in prior to July 5, 2018, are potential victims of this data breach and the company notify to all users via email as well as onsite and with mobile notifications, however, given the volume of users affected.

According to 500px, following Steps are taken to protect their customer from future attacks.

  • Given the nature of the personal data involved, we have already forced a reset of all MD5-encrypted passwords, and a system-wide password reset is underway.
  • We have vetted access to our servers, databases, and other sensitive data-storage services.
  • We have and are continuing to monitor our source code, both public-facing and internal, to protect against security issues.
  • We are partnering with leading experts in cyber security to further secure our website, mobile apps, internal systems, and security processes.
  • We are modifying our internal software development process.
  • We are continuing to upgrade our network infrastructure.


The company also states that it’s alerted the enforcement and has retained a private security firm to investigate the issue.

You can follow us on LinkedinTwitterFacebook for daily Cybersecurity updates also you can take the Best Cybersecurity courses online to keep your self-updated.

Also Read:

5 Best Workplace Practices To Prevent Data Breach

Houzz Suffers a Data Breach, Alerts Users to Change Password

Airbus Data Breach – Hackers Stolen Employee Sensitive & Personal Data

773 Million Credentials of Email & Password leaked in Massive Data Breach – Biggest Data Dump Ever Found on a Decade

Balaji

BALAJI is an Ex-Security Researcher (Threat Research Labs) at Comodo Cybersecurity. Editor-in-Chief & Co-Founder - Cyber Security News & GBHackers On Security.

Recent Posts

Docusnap for Windows Flaw Exposes Sensitive Data to Attackers

A recently disclosed vulnerability in Docusnap's Windows client software (CVE-2025-26849) enables attackers to decrypt sensitive…

54 minutes ago

CISA Warns of Active Exploitation of Microsoft Windows Win32k Vulnerability

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added CVE-2018-8639, a decade-old Microsoft Windows privilege…

1 hour ago

Update Alert: Google Warns of Critical Android Vulnerabilities Under Exploit

Google’s March 2025 Android Security Bulletin has unveiled two critical vulnerabilities—CVE-2024-43093 and CVE-2024-50302—currently under limited,…

4 hours ago

BigAnt Server 0-Day Vulnerability Lets Attackers Run Malicious Code Remotely

A critical vulnerability in BigAntSoft's enterprise chat server software has exposed ~50 internet-facing systems to…

4 hours ago

Bubba AI, Inc. is Launching Comp AI to Help 100,000 Startups Get SOC 2 Compliant by 2032.

With the growing importance of security compliance for startups, more companies are seeking to achieve…

6 hours ago

IBM Storage Virtualize Flaws Allow Remote Code Execution

Two critical security flaws in IBM Storage Virtualize products could enable attackers to bypass authentication…

6 hours ago