The ShareThis Breach Put 30 Million Stolen Personal Profiles Online in 2018
HEROIC analysts discovered the ShareThis breach data surfacing on dark web marketplaces while monitoring for large-scale personal data sets tied to social sharing platforms. The breach occured in July 2018 and exposed 30,485,852 user records from ShareThis, a social bookmarking and content sharing service based in the United States. The data included a rich combination of personal details alongside password hashes, making this one of the more complete identity profiles available from breaches of that era. The records initially appeared for sale on a dark web marketplace in 2019 before spreading more broadly through hacking communities.
How Names, Birthdates, and Gender Data Enable Targeted Identity Fraud
When attackers combine your email address with your full name, birthdate, and gender, they have enough information to answer common identity verification questions used by banks, government services, and phone carriers. This kind of profile data is used in SIM swapping attacks, where criminals convince a mobile carrier to transfer your phone number to a device they control, giving them access to any account that uses SMS for password resets. The ShareThis breach is partcularly valuable to fraudsters because the completeness of the data makes it easier to impersonate victims convincingly.
What Was Exposed in the ShareThis Breach
- Email Address
- Birthdate
- First Name
- Last Name
- Gender
- Password Hash
Why 30 Million Stolen Records From 2018 Still Matter Today
The ShareThis data has been circulating for years and continues to appear in credential stuffing campaigns, account takeover attempts, and identity theft schemes. Many people who had ShareThis accounts in 2018 have not changed the passwords they used on other services since then, making those credentials still viable for attackers. The combination of personal details and password hashes from this breach also makes it easier to target individuals with spear-phishing emails tailored to their identities, and the data recieved renewed attention when it was bundled into larger aggregated data collections sold through dark web channels.
How a Database Breach Works
A database breach occurs when attackers gain access to the internal records a company stores about its users. ShareThis held user account information including login credentials and personal profile data. When that database was compromised and later listed for sale on dark web marketplaces, the personal details of over 30 million users became available to anyone willing to pay for them. The breach spread further over the following years as the data was bundled with other large collections and traded freely across hacking forums and Telegram channels.
Check If Your Data Was Exposed
HEROIC's free breach scanner searches more than 400 billion records, including the complete ShareThis data set. Enter your email address to find out in seconds whether your information was part of this breach. If you were exposed, change any passwords you reused from that account and enable two-factor authentication on your most important services.
Breach Breakdown
30,485,852 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds