Tianya 2011 Data Breach

Tianya Chinese Internet Forum Breach (2011): 29 Million User Accounts Including Passwords Exposed

Online Community · General discussion, blogging, and social community content · Large-scale web forum · China

Tianya Chinese Internet Forum Breach (2011): 29 Million User Accounts Including Passwords Exposed

Major Chinese internet discussion forum (now defunct).

Confirmed · ObscureIQ Intelligence
Breach Risk Index i
14/100
Lower riskHigher risk
Lower: limited current risk based on data value and recency.
Data Sensitivity i
Standard
Exposed data is largely lower-sensitivity. Standard identity-protection precautions are advised.
29.0MRecords
2011Year

The Breach Risk Index (BRI) is a proprietary 0–100 score rating how dangerous a breach is right now, based on how recently the data has been circulating on the dark web and how valuable it is to attackers.

Classification Tags
Social NetworkingCommunityUsers2011

Breach Summary

In December 2011, China’s largest forum Tianya was hacked and 29,020,808 accounts were exposed as part of a wave of Chinese site breaches that month. The published data came from a backup predating 2009, when Tianya stored credentials in plaintext, and included email addresses, names, usernames, and plaintext passwords.

Full threat analysis, exploitation vectors, and principal guidance below.

11 additional sections · verified field analysis · defensive doctrine

Querying breach corpus…
Cross-referencing exposed field types…
Resolving threat-actor attribution…
Compiling principal risk advisory…

29.0M records analyzed

About Tianya

Tianya Club was one of China’s largest online forums and social communities, hosting discussion across a wide range of topics for a massive user base.

Why They Hold Your Data

Large web forums collect user accounts, emails, usernames, messages, posts, and long-term discussion history tied to blogging, social interaction, and community participation.

Recent Developments

Tianya moved to encrypted password storage in 2010; the leaked data came from an older backup and the platform later declined in prominence.

Data Points Exposed

4 verified field types
Email Address
Full Name
Password High
Username

Breach Impact

Plaintext passwords require no cracking, so despite their age the credentials drive credential-stuffing risk wherever users reused them, especially across Chinese-language services.

Exploitation & Downstream Threats

• Credential stuffing against reused passwords across other platforms | • Targeted phishing campaigns using exposed email addresses

Principal Risk Advisory

What this means for a principal

A social-platform breach: profile and contact-graph data supports impersonation, enrichment and social engineering. For a high-profile principal the main risk is credible impersonation and enrichment of existing exposure.

What You Should Do

  1. Reset any reused passwords and enable MFA on email first, then financial accounts.
  2. Do not use unofficial 'am I affected' lookups; several are themselves harvesting operations.

How ObscureIQ Can Help

  1. Corpus confirmation: determine whether and where the principal (plus household and staff) appear in this dataset and which specific fields are exposed for them.
  2. Exposure mapping: cross-reference the exposed identifiers against broker-available data to size and prioritize the principal's wider footprint.
  3. ThreatWatch tuned to this incident's identifiers and misuse pattern (impersonation and targeting patterns, not generic credential monitoring).
This breach is linked to the China 2011-2012 breach wave campaign (8 related breaches tracked by ObscureIQ). See the full campaign analysis →

Protect Yourself

Check If You're Affected

Enter your email to check whether your data appears in this breach. We’ll send a 6-digit code to confirm it’s your address.

High-Risk? Get an Exposure Audit

Executives, public figures, and high-visibility operators can receive tailored exposure intelligence and hardening guidance.

Request Consultation