1.8 Million Passwords From the Pixlr Breach Are Fueling Attacks Now
HEROIC analysts recieved and flagged the Pixlr breach after noticing a sharp uptick in credential stuffing activity tied to creative platform accounts. The breach, originally occuring on March 20, 2019, exposed 1,844,735 user records from Pixlr, a widely used free online photo editing tool based in Colombia. The leaked data included email addresses, hashed passwords, social media information, and full names, all of which have been quietly circulating in underground markets for years.
Why Hashed Passwords and Social Media Data Are a Dangerous Combination
Attackers who get hold of this kind of data do not just sit on it. SHA1 password hashes are partcularly vulnerable to cracking using tools that are freely available online. Once a password is cracked, it can be tested across dozens of other platforms automatically. Combined with social media profile data, attackers can impersonate victims, reset account credentials using security questions, or launch targeted phishing campaigns that feel eerily personal.
What Was Exposed in the Pixlr Breach
- Email Address
- Social Media
- First Name
- Last Name
- Password Hash
Why the Pixlr Breach Still Puts Millions at Risk Today
Even years after a breach, the risk does not disappear. People who used Pixlr in 2019 may have used the same password on their email, banking, or work accounts. Attackers use credential stuffing tools to automatically try those old passwords across hundreds of websites. This kind of attack leads to account takeover, identity theft, and in some cases financial fraud. The fact that real names and social media data were also exposed makes it beleive that targeted phishing attacks using this data are still happening today.
How Database Breaches Work
A database breach happens when an attacker gains unauthorized access to a company's stored user data. This can happen through weak passwords on the database itself, an unpatched software vulnerability, or a misconfigured server that is accidentally left open to the internet. Once inside, attackers can copy millions of records in minutes. The company often does not know it happened until the data shows up for sale online.
Check If Your Data Was Exposed
HEROIC's free breach scanner checks your email address against a database of over 400 billion compromised records, including breaches like Pixlr. Find out in seconds whether your information has been exposed and what steps you should take to protect yourself.
Breach Breakdown
1,844,735 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds