tumblr 2013 Data Breach

Tumblr Microblogging Platform Breach (2013): 65 Million User Email Addresses & Salted Passwords Exposed

Platform · Blogging and social media · Content publishing platform · Global

Tumblr Microblogging Platform Breach (2013): 65 Million User Email Addresses & Salted Passwords Exposed

Microblogging and social media platform.

Confirmed · ObscureIQ Intelligence
Breach Risk Index i
14/100
Lower riskHigher risk
Lower: limited current risk based on data value and recency.
Data Sensitivity i
Standard
Exposed data is largely lower-sensitivity. Standard identity-protection precautions are advised.
65.5MRecords
2013Year

The Breach Risk Index (BRI) is a proprietary 0–100 score rating how dangerous a breach is right now, based on how recently the data has been circulating on the dark web and how valuable it is to attackers.

Classification Tags
Cloud MisconfigurationSocial NetworkingCommunityUsers2013

Breach Summary

Tumblr suffered a credential breach in early 2013 that exposed approximately 65.5 million user accounts. The compromised data was not discovered publicly until 2016, when it appeared for sale on dark web marketplaces alongside similarly delayed breaches from LinkedIn and MySpace. The breach pathway involved a direct system compromise, though the precise technical method was not fully disclosed. The exposed data included email addresses and passwords. The passwords were stored as salted SHA-1 hashes, meaning they were not stored in plain text, but SHA-1 is a weak hashing standard by modern security standards and can be cracked with sufficient computing power. For Tumblr users, the platform's pseudonymous nature adds a distinct risk: exposed email addresses can be cross-referenced with other data to link anonymous online identities to real people, along with years of posts, communities, and personal expression tied to those accounts. Tumblr, operating under Yahoo's ownership at the time, notified affected users and required password resets following the data's public emergence in 2016. No significant regulatory action was publicly reported in connection with this breach. Anyone with a Tumblr account predating 2013 should treat their credentials as compromised, particularly if they reused the same password on other services, as credential stuffing attacks routinely exploit aged breach data.

Full threat analysis, exploitation vectors, and principal guidance below.

10 additional sections · verified field analysis · defensive doctrine

Querying breach corpus…
Cross-referencing exposed field types…
Resolving threat-actor attribution…
Compiling principal risk advisory…

65.5M records analyzed

About tumblr

Tumblr is a microblogging and social media platform built around short-form multimedia posts, creative expression, and pseudonymous community identity. It was founded in 2007 by David Karp, acquired by Yahoo in 2013 for $1.1 billion, passed to Verizon through its Yahoo acquisition in 2017, and sold to Automattic — the company behind WordPress.com — for a reported sum of less than $3 million in 2019. The platform continues to operate under Automattic as a niche creative and fandom community.

Why They Hold Your Data

Social publishing platforms collect user accounts, emails, usernames, passwords, messages, posts, social relationships, and engagement history across blogging and community workflows.

Recent Developments

Tumblr has operated under Automattic since 2019 with significantly reduced scale and cultural footprint from its peak. The platform introduced an adult content ban in December 2018 — prior to the Automattic acquisition — which triggered a large user exodus. Automattic CEO Matt Mullenweg has publicly acknowledged the platform is not profitable. Tumblr introduced a paid subscription tier in 2022. It remains active as a niche community platform but its days as a mainstream social network are long past.

Data Points Exposed

2 verified field types
Email Address
Password High

Breach Impact

In early 2013 Tumblr suffered a credential breach exposing approximately 65 million email addresses and passwords stored as salted SHA-1 hashes. The data did not surface publicly until 2016, when it was put up for sale on dark web marketplaces alongside similarly delayed breaches from LinkedIn, MySpace, and other major platforms. Tumblr, then operating under Yahoo's ownership, notified affected users and required password resets. The incident was part of the "mega-breach" wave of 2016 that revealed how many large credential databases from the early 2010s had been quietly circulating among criminal networks for years before becoming public knowledge.

Exploitation & Downstream Threats

• Credential stuffing against reused passwords across other platforms | • Targeted phishing campaigns using exposed email addresses

Principal Risk Advisory

What this means for a principal

A social-platform breach: profile and contact-graph data supports impersonation, enrichment and social engineering. For a high-profile principal the main risk is credible impersonation and enrichment of existing exposure.

What You Should Do

  1. Reset any reused passwords and enable MFA on email first, then financial accounts.
  2. Do not use unofficial 'am I affected' lookups; several are themselves harvesting operations.

How ObscureIQ Can Help

  1. Corpus confirmation: determine whether and where the principal (plus household and staff) appear in this dataset and which specific fields are exposed for them.
  2. Exposure mapping: cross-reference the exposed identifiers against broker-available data to size and prioritize the principal's wider footprint.
  3. ThreatWatch tuned to this incident's identifiers and misuse pattern (impersonation and targeting patterns, not generic credential monitoring).

Protect Yourself

Check If You're Affected

Enter your email to check whether your data appears in this breach. We’ll send a 6-digit code to confirm it’s your address.

Get Free Breach Alerts

Be the first to know when new breaches are disclosed. Free forever — confirm your email with a 6-digit code.

High-Risk? Get an Exposure Audit

Executives, public figures, and high-visibility operators can receive tailored exposure intelligence and hardening guidance.

Request Consultation