The LookBook Leak Contains More Records Than Delaware Has Residents
LookBook (lookbook.nu) was a social platform for fashion enthusiasts where users posted outfit photos and discovered style inspiration from around the world. In August 2012, the platform was breached, exposing records for over 1.07 million registered users. The data was not publicly disclosed until June 2016, when it appeared for sale on dark web marketplaces, meaning users were unaware for four years that their data had been stolen. The most alarming detail: passwords were stored in plaintext, meaning attackers obtained working passwords without any cracking required.
Why LookBook Breach Is Dangerous
Plaintext password storage is one of the most serous failures in data security. There is no hashing to crack, no rainbow table to run, and no decryption step. Any attacker who obtained the LookBook database got a ready-to-use list of email addresses and working passwords. For every user who reused that same password on their email account, bank, or social media profiles, those accounts became instantly vulnerable when this data started circulating in 2016. The four-year disclosure gap made this worse: users could not take action they didn't know was needed.
What Was Exposed in the LookBook Leak
- Email Address
- Plaintext Password
- Username
- IP Address
- Birthday
Why This LookBook Data Puts You at Risk
Birthday data combined with a username and an email address provides enough information to answer security questions on many platforms, including banking sites. If you registered on LookBook before 2012 and the email address you used is still active, that account should be reviewed now. Any platform where you used the same password as your LookBook account should definitly be updated, even if that account is years old.
How Plaintext Password Breaches Accelerate Account Takeovers
When a platform stores passwords in plaintext, a breach of that database is immediatly actionable for attackers. There is no delay for cracking. The email-password pairs are loaded directly into credential stuffing tools and tested against banks, email providers, streaming services, and e-commerce sites. LookBook's breach occured in August 2012 and was disclosed in 2016, giving attackers years to use the data before most users became aware. The 1.07 million records represent 1.07 million potentially open doors across every other platform those users ever signed up for.
Check If Your Data Was Exposed
HEROIC's free breach search checks your email against 400 billion+ compromised records, including the LookBook dataset. Search now to see if your account was included. If you used your LookBook password anywhere else, change it on every platform immediately.
Breach Breakdown
1,074,283 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds