The piZap Breach Means Someone May Already Have Your Password
HEROIC analysts monitoring dark web marketplaces identified the piZap breach data actively circulating years after it first occured in December 2017. The breach exposed nearly 39 million records from this popular online photo editing service, including email addresses, usernames, real names, gender information, social media profile links, and SHA-1 password hashes. What makes this breach partcularly concerning is that the data was bundled and sold on dark web forums in 2019, meaning it has been in the hands of cybercriminals for years and continues to resurface in new attack campaigns.
How Your Password Hash and Email Put You at Risk
SHA-1 password hashes from the piZap breach are not safe. Modern cracking tools can break SHA-1 hashes in minutes or hours, giving attackers your actual password. When that is combined with your email address and real name from the same breach, criminals have everything they need to attempt logins on banking, email, and social media accounts. This type of credential attack is highly accessable to even low-skill criminals who purchase these datasets cheaply on dark web markets.
What Was Exposed in the piZap Breach
- Email Address
- Username
- Social Media Profile Links
- First Name
- Last Name
- Gender
- Password Hash (SHA-1)
Why the piZap Breach Still Threatens You Today
Old breaches do not expire. Criminals use piZap data for credential stuffing attacks, where they automatically try your email and password combination on hundreds of other websites. If you reused that password anywhere else, those accounts are at serious risk of takeover. Your name, gender, and social media links also make you an easy target for convincing phishing emails and identity theft schemes that can lead to financial fraud.
How a Database Breach Works
A database breach happens when attackers find a vulnerability in a website or its server and gain unauthorized access to the underlying database where user information is stored. In piZap's case, the attacker copied millions of user records, including the stored password hashes, and later sold that data on dark web marketplaces. The website may continue working normally while all of that stolen data is quietly being traded among criminals.
Check If Your Data Was Exposed
HEROIC offers a free breach scanner that searches across more than 400 billion records, including the piZap breach, to tell you exactly what information of yours has been exposed. Run a free scan today to find out if your email, password, or personal details are in the hands of cybercriminals and learn what steps to take to protect yourself.
Breach Breakdown
38,918,973 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds