← Back to list

A data breach at Gravatar exposed 167 million profiles. What Does This Imply for You?

Back in October 2020 Carlo Di Dato, a security researcher, uncovered a method to obtain data about Gravatar users by exploiting a…

Jennifer Oseana · 2021-12-09 20:51 · 2 claps · 2.2 min read
#cybersecurity #data-leak #cybercrime #hacking
Open on Medium ↗
Wiki topics: 🔒 · Cybersecurity

A data breach at Gravatar exposed 167 million profiles. What Does This Imply for You?

Back in October 2020 Carlo Di Dato, a security researcher, uncovered a method to obtain data about Gravatar users by exploiting a vulnerability in the online avatar service.

Despite the fact that the data was ostensibly public, Di Dato cautioned the community that “it’s doubtful users are aware their data may be retrieved by querying Gravatar in a way that should not be feasible.”

Fast forward to December 2021. “167 million names, usernames, and encrypted email addresses used to reference users’ avatars were scraped and circulated across the hacking community,” according to HaveIBeenPwned. Just under 114 million encrypted records, or 68 percent, were broken and disseminated alongside the source hash, revealing the original email address and contents.

Gravatar is a service that allows users to create unique avatars. Users can create an account using only their email address and a digital avatar to be associated with it. Gravatar works with WordPress, GitHub, and other platforms, so when a user comments, the avatar is immediately displayed.

What impact does this have on you?

If you have a WordPress or GitHub account, you almost certainly also have a Gravatar account, and your information was scraped as part of the leak. But there’s no need to still be concerned.

While the situation isn’t ideal, the data that has been released simply contains names, usernames, and email addresses. There’s no reason to suspect that passwords or other sensitive data were stolen.

However, fraudsters can still use the scraped information against you. Hackers, for example, can crack your password just by knowing your e-mail address. Your account can be easily hacked if your password is weak or has been reused on several accounts.

Scammers can cyberstalk you and target you with spam or spear-phishing using only your name and e-mail address. Spear-phishing, unlike traditional phishing, consists of persuasive tailored messages directed at a single individual of interest.

The victim is duped into installing malware or giving their password and banking information after being “speared.” The criminals then take control.

Last but not least, hackers can combine the scraped data with other personal information gathered on the Dark Web to create a comprehensive digital profile and exploit it to conduct fraud using your identity.

What can you do to keep yourself safe?

Data breaches happen all the time, whether we like it or not, and while changing our names or e-mail addresses isn’t an option, we may take other actions to protect our accounts:

  • Utilize a solid, extraordinary secret phrase, ideally one that is irregular produced and safely put away in a secret word director
  • Never utilize similar secret phrase on numerous records and never reuse old passwords
  • On the off chance that you have any motivation to accept a record was compromised, change your secret phrase right away
  • Keep an eye out for obscure messages, particularly messages that ask you to make a quick move, and don’t tap on dubious connections
  • Continuously twofold check the email sender, regardless of whether the message appears to come from a solid source
  • Remain informed

메타데이터
post_id
7c99f2dead9e
slug
a-data-breach-at-gravatar-exposed-167-million-profiles-what-does-this-imply-for-you-7c99f2dead9e
url
https://medium.com/@jen_ose/a-data-breach-at-gravatar-exposed-167-million-profiles-what-does-this-imply-for-you-7c99f2dead9e
canonical_url
https://medium.com/@jen_ose/a-data-breach-at-gravatar-exposed-167-million-profiles-what-does-this-imply-for-you-7c99f2dead9e
author_url
https://medium.com/@jen_ose
status
ok
fetched_at
2026-07-27 18:07:00