Avvo 2019 Data Breach

Avvo Online Legal Marketplace Breach (2019): 4.1 Million User Accounts Including Passwords Exposed

Platform · Legal services marketplace · Lawyer directory and client matching platform · USA

Avvo Online Legal Marketplace Breach (2019): 4.1 Million User Accounts Including Passwords Exposed

Online legal services marketplace.

Confirmed · ObscureIQ Intelligence
Breach Risk Index i
34/100
Lower riskHigher risk
Moderate: notable exposure with meaningful misuse potential.
Data Sensitivity i
Standard
Exposed data is largely lower-sensitivity. Standard identity-protection precautions are advised.
4.1MRecords
2019Year

The Breach Risk Index (BRI) is a proprietary 0–100 score rating how dangerous a breach is right now, based on how recently the data has been circulating on the dark web and how valuable it is to attackers.

Classification Tags
Cloud MisconfigurationLegalProfessional ServicesUsers2019

Breach Summary

Avvo, a U.S.-based online legal services marketplace and lawyer directory, suffered a data breach that came to public attention in approximately December 2019 when an alleged dataset of Avvo user accounts was published to an online hacking forum. The dataset was subsequently used in extortion campaigns targeting affected users, with users receiving 'you've been hacked' extortion emails to email addresses that they had used exclusively for their Avvo accounts. The breach was reported to Have I Been Pwned in 2022 after a user identified the extortion pattern and alerted Troy Hunt. Hunt attempted to disclose the breach to Avvo over the course of a week without receiving any response. The dataset's authenticity was eventually verified by correlating the records with HIBP subscribers' confirmed Avvo accounts, and the breach was indexed by HIBP and Mozilla Monitor on April 15, 2022. The original date of the underlying compromise is uncertain and may date back earlier than December 2019. The breach affected approximately 4.1 million user accounts based on records indexed by Have I Been Pwned, with 4,101,101 unique email addresses verified. Compromised fields included email addresses and SHA-1-hashed password values. SHA-1 hashing is a deprecated cryptographic algorithm that is significantly weaker than modern bcrypt, scrypt, or Argon2 hashing and is increasingly vulnerable to GPU-accelerated brute-force cracking. The hash format suggests the underlying password values are recoverable for many users, particularly those who chose short or commonly used passwords. For affected users, the practical risk profile combines credential-reuse exposure with legal-services-specific reputational risk. The combination of email address and recoverable password value supports credential-stuffing attacks against other accounts where the same password was reused. More distinctively, inclusion in the Avvo dataset confirms that the user has interacted with a legal-services marketplace, which can support targeted phishing referencing legal questions, attorney consultations, or potentially sensitive case categories. The dataset has been actively used in extortion campaigns targeting users at Avvo-specific email addresses, with extortion emails claiming fictional compromise of devices and demanding cryptocurrency payment. Affected users who receive extortion emails should not pay ransom demands as the emails typically rely on the email-address exposure for credibility rather than any actual device compromise. Users should change any reused passwords on other accounts, enable two-factor authentication where available, and treat unsolicited contact referencing Avvo, attorney consultations, or legal questions with caution. The active use of the dataset in extortion campaigns means affected users should expect ongoing exposure rather than a time-limited incident.

Full threat analysis, exploitation vectors, and principal guidance below.

10 additional sections · verified field analysis · defensive doctrine

Querying breach corpus…
Cross-referencing exposed field types…
Resolving threat-actor attribution…
Compiling principal risk advisory…

4.1M records analyzed

About Avvo

Avvo is a U.S.-based online legal services marketplace and lawyer directory that connects consumers seeking legal services with attorneys and provides public profile pages for individual lawyers. Headquartered in Seattle, Washington and founded in 2006, Avvo operates as a referral and reputation platform with attorney ratings, peer endorsements, client reviews, and a question-and-answer service through which users can submit legal questions for attorneys to answer publicly. As an account-based legal-services marketplace, Avvo maintains substantial user account data including consumer identity, attorney profile records, legal-question submissions, attorney-client matching records, and login credentials tied to legal-services discovery and matching workflows.

Why They Hold Your Data

Legal-services marketplaces collect client identity, inquiry details, attorney relationships, contact records, case-interest signals, and messaging tied to legal search and matching workflows.

Recent Developments

The Avvo breach surfaced publicly in early 2022 when Have I Been Pwned subscribers began receiving extortion emails to their Avvo-specific email addresses, indicating the dataset was being actively used in extortion campaigns rather than merely circulating among breach-trading communities. Have I Been Pwned founder Troy Hunt published a detailed blog post in April 2022 documenting the difficulty of disclosing the breach to Avvo, including multiple attempts over the course of a week that received no response. The breach was eventually verified by correlating the dataset with HIBP subscribers' confirmed Avvo accounts, and was indexed by HIBP and Mozilla Monitor on April 15, 2022. Avvo has not publicly detailed the original incident, the specific vulnerability that enabled the compromise, or post-incident security measures.

Data Points Exposed

2 verified field types
Email Address
Password High

Breach Impact

The institutional impact on Avvo has been limited because of the company's lack of public response and the absence of formal regulatory action. Civil litigation has been minimal. The reputational impact within the legal-services marketplace category has been modest, although Troy Hunt's published account of Avvo's unresponsiveness to breach-disclosure attempts has been cited in security commentary about disclosure failures and corporate breach-response practices. The case has not generated formal regulatory or industry action, despite the active use of the dataset in extortion campaigns targeting affected users.

Exploitation & Downstream Threats

• Credential stuffing against reused passwords across other platforms | • Targeted phishing campaigns using exposed email addresses

Principal Risk Advisory

What this means for a principal

A consumer-service breach: contact and account data supports phishing, account takeover and profile enrichment. For a high-profile principal the main risk is credible impersonation and enrichment of existing exposure.

What You Should Do

  1. Reset any reused passwords and enable MFA on email first, then financial accounts.
  2. Do not use unofficial 'am I affected' lookups; several are themselves harvesting operations.

How ObscureIQ Can Help

  1. Corpus confirmation: determine whether and where the principal (plus household and staff) appear in this dataset and which specific fields are exposed for them.
  2. Exposure mapping: cross-reference the exposed identifiers against broker-available data to size and prioritize the principal's wider footprint.
  3. ThreatWatch tuned to this incident's identifiers and misuse pattern (impersonation and targeting patterns, not generic credential monitoring).

Protect Yourself

Check If You're Affected

Enter your email to check whether your data appears in this breach. We’ll send a 6-digit code to confirm it’s your address.

Get Free Breach Alerts

Be the first to know when new breaches are disclosed. Free forever — confirm your email with a 6-digit code.

High-Risk? Get an Exposure Audit

Executives, public figures, and high-visibility operators can receive tailored exposure intelligence and hardening guidance.

Request Consultation