The Imgur Leak Exposed Nearly 900,000 Plaintext Passwords
The Imgur Data Breach: What HEROIC Found
HEROIC analysts identified a breach tied to Imgur, the popular image hosting platform, originating in 2013. HEROIC's records show 876,880 exposed accounts tied to this incident, with data limited to email addresses and plaintext passwords. Public reporting at the time of Imgur's own disclosure described a wider leaked dataset of around 1.7 million email and password pairs that surfaced more than four years after the original breach, in November 2017. Imgur has stated it stored passwords as SHA-256 hashes and moved to bcrypt hashing in 2016, which suggests that by the time this data circulated, many of the original hashes had already been cracked into plaintext.
Why This Is Dangerous for Imgur Users
Plaintext passwords remove any barrier between an attacker and your account. There is no hash to crack and no delay to buy you time to react. Anyone with access to this dataset can log in immediately using the exact email and password combination on file, and if that password was ever reused on another site, that account is exposed too.
What Was Exposed in the Imgur Leak
- Email addresses
- Plaintext passwords
Why This Matters: A Leak That Outlives the Headline
This breach shows how a single incident can resurface and stay dangerous for years. Even though the original compromise happened in 2013 and was disclosed in 2017, the plaintext passwords in this dataset remain just as usable today as the day they leaked. Attackers use datasets like this for credential stuffing, testing the same email and password against email providers, social platforms, and banks, which is how old breaches keep fueling new account takeovers and identity theft.
How a Database Breach Like This Happens
This incident is classified as a database breach. In Imgur's case, the exposure stemmed from a 2013 database compromise that was not identified and disclosed until years later. Once a database is stolen, attackers can work on cracking any hashed passwords at their leisure, which is why a breach can appear as an SHA-256 hash list on day one and resurface with those same passwords in readable, plaintext form years afterward.
Check If You Are Affected
If you have ever had an Imgur account, especially one created before 2016, it is worth checking your exposure directly. HEROIC's free breach scanner checks your email address against more than 400 billion breached records, including this one, so you can confirm in seconds whether your password was exposed and update it anywhere you reused it.
Breach Breakdown
876,880 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds