Sunday, April 13, 2025
HomeData BreachDisqus confirms it's been hacked and more than 17.5 Million Users Details...

Disqus confirms it’s been hacked and more than 17.5 Million Users Details Exposed

Published on

SIEM as a Service

Follow Us on Google News

Disqus the most famous commenting system late today confirmed the data breach that took place in the summer of 2012, which exposed more than 17.5 million user accounts online.

Leaked details include email addresses, Disqus usernames, sign-up dates, and last login dates in plain text for 17.5mm users, but passwords are hashed with SHA-1 and salted, which protects the compromised account.

Also Read POS Malware Breach at Sonic Affected Millions of Credit & Debit Cards

- Advertisement - Google News

This breach was identified by the Aussie security researcher Troy Hunt, and according to Hunt’s tweet, Disqus took 23 hours and 42 minutes from initial private disclosure to public notification.

User Impact

Email address is in plain text, so affected users may receive Spam emails. They believe the data was not widely exposed and they also confirmed the exposed data is from July 2012.

Right now there isn’t any evidence of unauthorized logins occurring in relation to this. No plain text passwords were exposed, but it is possible for this data to be decrypted (even if unlikely). As a security precaution, we have reset the passwords for all affected users. We recommend that all users change passwords on other services if they are shared.Disqus says.

So if you started using Disqus after July 2012, then your account is not impacted by the breach.

Safety Measures were taken by Disqus

They started notifying users about the breach and forcing the reset of passwords for all affected users.Also, they tighten the database security.

They also said that toward the end of 2012 we changed our password hashing algorithm from SHA1 to bcrypt.

Also Read Deloitte Hacked by Cyber Criminals and Revealed Client & Employee’s Secret Emails

Gurubaran
Gurubaran
Gurubaran is a co-founder of Cyber Security News and GBHackers On Security. He has 10+ years of experience as a Security Consultant, Editor, and Analyst in cybersecurity, technology, and communications.

Latest articles

Threat Actors Manipulate Search Results to Lure Users to Malicious Websites

Cybercriminals are increasingly exploiting search engine optimization (SEO) techniques and paid advertisements to manipulate...

Hackers Imitate Google Chrome Install Page on Google Play to Distribute Android Malware

Cybersecurity experts have unearthed an intricate cyber campaign that leverages deceptive websites posing as...

Dangling DNS Attack Allows Hackers to Take Over Organization’s Subdomain

Hackers are exploiting what's known as "Dangling DNS" records to take over corporate subdomains,...

HelloKitty Ransomware Returns, Launching Attacks on Windows, Linux, and ESXi Environments

Security researchers and cybersecurity experts have recently uncovered new variants of the notorious HelloKitty...

Resilience at Scale

Why Application Security is Non-Negotiable

The resilience of your digital infrastructure directly impacts your ability to scale. And yet, application security remains a critical weak link for most organizations.

Application Security is no longer just a defensive play—it’s the cornerstone of cyber resilience and sustainable growth. In this webinar, Karthik Krishnamoorthy (CTO of Indusface) and Phani Deepak Akella (VP of Marketing – Indusface), will share how AI-powered application security can help organizations build resilience by

Discussion points


Protecting at internet scale using AI and behavioral-based DDoS & bot mitigation.
Autonomously discovering external assets and remediating vulnerabilities within 72 hours, enabling secure, confident scaling.
Ensuring 100% application availability through platforms architected for failure resilience.
Eliminating silos with real-time correlation between attack surface and active threats for rapid, accurate mitigation

More like this

Sensata Technologies Breached: Ransomware Attack Key Systems

Sensata Technologies Holding PLC, a global leader in sensor solutions and electrical protection, is...

Hackers Claim WooCommerce Breach Exposing 4.4 Million Customer Records

A hacker operating under the alias “Satanic” has claimed responsibility for a massive data...

Oracle Confirms Breach: Hackers Stole Client Login Credentials

Oracle Corporation has officially confirmed a cybersecurity breach in which hackers infiltrated its systems...