Disqus 2012 Data Breach

Disqus Website Comment Platform Breach (2012, Disclosed 2017): 27 Million User Accounts Including Hashed Passwords Exposed

Platform · Website commenting and engagement tools · SaaS discussion platform · Global

Disqus Website Comment Platform Breach (2012, Disclosed 2017): 27 Million User Accounts Including Hashed Passwords Exposed

Comment hosting platform for websites.

Confirmed · ObscureIQ Intelligence
Breach Risk Index i
23/100
Lower riskHigher risk
Lower: limited current risk based on data value and recency.
Data Sensitivity i
Standard
Exposed data is largely lower-sensitivity. Standard identity-protection precautions are advised.
27.8MRecords
2012Year

The Breach Risk Index (BRI) is a proprietary 0–100 score rating how dangerous a breach is right now, based on how recently the data has been circulating on the dark web and how valuable it is to attackers.

Classification Tags
ProductivitySaaSUsers2012

Breach Summary

Disqus, a comment hosting platform embedded across major news sites, blogs, and digital media properties worldwide, suffered a data breach in July 2012 that went undetected for over five years. The intrusion was not discovered until October 2017, when the stolen data surfaced. The breach affected approximately 27.8 million user accounts. The attack vector was not publicly identified. The exposed data included email addresses, usernames, and passwords stored as salted SHA-1 hashes. SHA-1 is an older hashing algorithm that, while better than storing passwords in plain text, is now considered weak and crackable with modern tools. Users who had logged in through social accounts such as Google or Facebook had no stored password exposed, but their account references were included. Because Disqus operates across thousands of third-party sites, the breach also exposes a risk specific to the platform: commenting history tied to a single Disqus identity can be used to correlate pseudonymous usernames with personal views, political opinions, or other identifying information across sites. No regulatory action or legal settlement specific to this breach has been publicly documented. Once the breach was discovered in 2017, Disqus disclosed the incident promptly and notified affected users, prompting password resets. People affected by this breach should treat any reused passwords as compromised, particularly if those credentials were used on other sites. The five-year gap between the intrusion and its discovery means exposed data had ample time to circulate before users had any opportunity to act.

Full threat analysis, exploitation vectors, and principal guidance below.

10 additional sections · verified field analysis · defensive doctrine

Querying breach corpus…
Cross-referencing exposed field types…
Resolving threat-actor attribution…
Compiling principal risk advisory…

27.8M records analyzed

About Disqus

Disqus is a comment hosting and community platform embedded on third-party websites to power reader discussion sections. Publishers integrate Disqus to replace native comment systems with a centralized, cross-site identity and moderation layer. The platform has been used by major news sites, blogs, and digital media properties globally. Disqus was acquired by Zeta Global in 2017.

Why They Hold Your Data

Commenting and engagement platforms collect user accounts, emails, usernames, passwords, IP addresses, and public discussion history across large networks of websites.

Recent Developments

Disqus continues to operate under Zeta Global's ownership as part of its marketing technology portfolio. The comment platform market has contracted as major publishers have disabled reader comments or moved to social media-based discussion. Disqus has maintained its presence among publishers that still host reader comments but its cultural prominence has diminished.

Data Points Exposed

3 verified field types
Email Address
Password High
Username

Breach Impact

In July 2012 Disqus was breached, though the incident was not discovered until October 2017 — a five-year gap between intrusion and discovery that is among the longer undetected dwell times in consumer platform breach history. Once discovered, Disqus disclosed the incident promptly. The exposed dataset of approximately 17.5 million records included email addresses, usernames, and passwords stored as salted SHA-1 hashes, along with some accounts with no stored password that had used social login. Disqus notified affected users and prompted password resets. No settlement or regulatory action specific to this breach has been prominently documented.

Exploitation & Downstream Threats

• Credential stuffing against reused passwords across other platforms | • Targeted phishing campaigns using exposed email addresses

Principal Risk Advisory

What this means for a principal

A consumer-service breach: contact and account data supports phishing, account takeover and profile enrichment. For a high-profile principal the main risk is credible impersonation and enrichment of existing exposure.

What You Should Do

  1. Reset any reused passwords and enable MFA on email first, then financial accounts.
  2. Do not use unofficial 'am I affected' lookups; several are themselves harvesting operations.

How ObscureIQ Can Help

  1. Corpus confirmation: determine whether and where the principal (plus household and staff) appear in this dataset and which specific fields are exposed for them.
  2. Exposure mapping: cross-reference the exposed identifiers against broker-available data to size and prioritize the principal's wider footprint.
  3. ThreatWatch tuned to this incident's identifiers and misuse pattern (impersonation and targeting patterns, not generic credential monitoring).

Protect Yourself

Check If You're Affected

Enter your email to check whether your data appears in this breach. We’ll send a 6-digit code to confirm it’s your address.

Get Free Breach Alerts

Be the first to know when new breaches are disclosed. Free forever — confirm your email with a 6-digit code.

High-Risk? Get an Exposure Audit

Executives, public figures, and high-visibility operators can receive tailored exposure intelligence and hardening guidance.

Request Consultation