Hjedd 2022 Data Breach

Hjedd Chinese Adult Content Platform Breach (2022): 13 Million User Accounts Including Passwords Exposed

Platform · Adult content and social interaction · Account-based content platform · Global

Hjedd Chinese Adult Content Platform Breach (2022): 13 Million User Accounts Including Passwords Exposed

Chinese adult content platform

Confirmed · ObscureIQ Intelligence
Limited DisclosureThis breach is handled differently. Because being connected to it can itself be sensitive, we do not confirm anyone’s presence publicly. Use the private exposure check at the bottom of this page.
Breach Risk Index i
65/100
Lower riskHigher risk
High and current: recent, valuable data circulating on the dark web now.
Data Sensitivity i
Restricted
Being associated with this breach can itself be harmful. Disclosure is limited and presence is not confirmed to unverified parties.
13.4MRecords
2022Year

The Breach Risk Index (BRI) is a proprietary 0–100 score rating how dangerous a breach is right now, based on how recently the data has been circulating on the dark web and how valuable it is to attackers.

Classification Tags
Researcher disclosureCloud MisconfigurationViceAdultUsers2022

Breach Summary

Hjedd, a Chinese-language adult content and NSFW social platform, was found in July 2022 to be operating an unsecured ElasticSearch database that exposed personal information for over 14 million users. Independent security researcher Anurag Sen discovered the exposed server via Shodan and confirmed that no authentication was required to access the data, which totaled more than 24 gigabytes of records. Sen disclosed the issue to Hjedd on multiple occasions, but the platform did not respond or secure the server, and the database continued to update with newly registered users' data while remaining publicly accessible. Cybercriminals subsequently posted a downloadable copy of the dataset, containing approximately 13.4 million unique user accounts, on a hacker forum. The breach affected approximately 13.4 million users in the publicly distributed dataset and over 14 million users in the broader exposed database. Compromised fields included usernames, nicknames, email addresses, phone numbers, member profile details, user comments, login IP addresses, bcrypt-hashed passwords, and direct messages exchanged between users. The exposure of direct messages is particularly consequential because these messages contain private communications about adult-content interests, sexual preferences, and arrangements between users. For affected users, the practical risk profile is unusually severe because of the platform's adult-content context and the inclusion of direct messages. The combination of email address, IP address, and bcrypt-hashed password creates credential-stuffing and account-takeover risk on other platforms where users may have reused the same credentials. More distinctively, inclusion in the dataset confirms an adult-content-platform relationship and may include private messages that explicitly describe the user's sexual interests, partners, or arrangements. This creates substantial extortion risk, in which attackers threaten to disclose the user's account or message history to family members, employers, or social networks unless ransom payments are made. Affected users who receive extortion attempts should not pay ransom demands, as payment does not stop further extortion and may invite additional attempts. Users should change passwords on any other accounts where the same password was reused, enable two-factor authentication where available, document all extortion communications, and report extortion attempts to law enforcement. Users should also be aware that bcrypt password hashes can be cracked over time as computing capacity increases.

Full threat analysis, exploitation vectors, and principal guidance below.

11 additional sections · verified field analysis · defensive doctrine

Querying breach corpus…
Cross-referencing exposed field types…
Resolving threat-actor attribution…
Compiling principal risk advisory…

13.4M records analyzed

About Hjedd

Hjedd was a Chinese-language adult content and NSFW (not safe for work) social platform with a substantial user base. The platform combined adult content distribution, user-generated content, account-based social features including direct messaging between users, and forum-style interaction. As an adult content platform of significant scale, Hjedd maintained user account identifiers, email addresses, usernames, login credentials, IP addresses, mobile phone numbers, member profile details, user comments, and direct messages exchanged between users. The platform's user base was concentrated in Chinese-speaking regions but registration was not geographically restricted.

Why They Hold Your Data

Adult social and content platforms collect highly sensitive account identifiers, emails, usernames, passwords, IP addresses, and usage activity tied to explicit-content participation.

Recent Developments

Independent security researcher Anurag Sen discovered the unsecured Hjedd database via Shodan in July 2022 and documented that the server was publicly accessible without authentication. Sen disclosed the issue to Hjedd on multiple occasions, but the platform did not respond or secure the server. The database remained exposed for an extended period, during which it continued to update with newly registered users' data. Cybercriminals discovered the exposure independently and posted a free download of the Hjedd database on a hacker forum that had emerged as an alternative to the seized RaidForums. Have I Been Pwned indexed the breach in October 2023 and DataBreach.com indexed it in February 2025. The case has been widely cited in security research as an example of misconfigured ElasticSearch exposures and unresponsive vendor remediation.

Data Points Exposed

4 verified field types
Email Address
IP Address
Password High
Username

Breach Impact

The institutional impact on Hjedd is difficult to assess given the platform's limited public profile and apparent unresponsiveness to disclosure. The platform did not issue a public statement, did not notify affected users, and reportedly did not secure the database in response to repeated researcher disclosure. Chinese regulatory authorities have not publicly announced enforcement action, and Hjedd faces no apparent civil litigation. Operationally, however, the breach exposed the platform's lack of basic security controls and continued operation of an unsecured database for an extended period, raising questions about user trust and ongoing data protection.

Exploitation & Downstream Threats

• Credential stuffing against reused passwords across other platforms | • Targeted phishing campaigns using exposed email addresses

Principal Risk Advisory

What this means for a principal

An intimate-data breach: preferences, orientation or explicit content linked to an identity create acute coercion and blackmail exposure. For a high-profile principal the main risk is credible impersonation and enrichment of existing exposure.

What You Should Do

  1. Reset any reused passwords and enable MFA on email first, then financial accounts.
  2. Do not use unofficial 'am I affected' lookups; several are themselves harvesting operations.

How ObscureIQ Can Help

  1. Corpus confirmation: determine whether and where the principal (plus household and staff) appear in this dataset and which specific fields are exposed for them.
  2. Exposure mapping: cross-reference the exposed identifiers against broker-available data to size and prioritize the principal's wider footprint.
  3. ThreatWatch tuned to this incident's identifiers and misuse pattern (impersonation and targeting patterns, not generic credential monitoring).
RD
Threat Actor: Researcher disclosure
Threat actor

Attribution based on available breach intelligence.

Read the full threat-actor profile →

Protect Yourself

Protect Yourself: Limited Disclosure

Check If You’re Affected: Verification Required

Because being associated with this breach can itself be harmful, we do not confirm whether anyone appears in it to unverified parties. Verify your identity to privately check whether your own data appears in this breach or related indexes.

We will only reveal whether a specific person appears in this breach to that person.

Get Free Breach Alerts

Be the first to know when new breaches are disclosed. Free forever — confirm your email with a 6-digit code.

High-Risk? Get an Exposure Audit

Executives, public figures, and high-visibility operators can receive tailored exposure intelligence and hardening guidance.

Request Consultation