WeHeartIt
We've observed a consistent trickle of older breaches resurfacing in recent months, often repackaged and sold as "new" leaks on various illicit marketplaces. What really struck us with the WeHeartIt data wasn't the novelty, but the sheer volume of credential reuse we observed across multiple unrelated platforms. This 2013 breach, only recently surfaced in 2017, continues to fuel password spraying attacks and credential stuffing attempts nearly a decade later. The longevity of this data underscores the persistent risk posed by older breaches, especially when combined with poor password hygiene.
WeHeartIt's 2013 Breach: A Decade of Credential Reuse
In November 2013, the image-based social network WeHeartIt experienced a significant data breach impacting 6,408,496 users. While the breach itself occurred years ago, it wasn't discovered and added to breach notification services like "Have I Been Pwned?" until October 2017. The extended delay between the breach and its public disclosure allowed the compromised credentials to circulate quietly, increasing the potential for misuse over a prolonged period. This case highlights the importance of proactive breach detection and timely notification.
The breach initially caught our attention due to the high percentage of exposed accounts exhibiting password reuse across other popular services. The data included usernames, email addresses, and password hashes. While approximately 80% of the passwords were protected with salted SHA-256 hashing, the remaining 20% utilized unsalted MD5, a significantly weaker hashing algorithm. This mix of hashing algorithms made a substantial portion of the passwords relatively easy to crack, further compounding the risk to affected users. The fact that unsalted MD5 was still in use in 2013 is a security red flag.
This breach matters to enterprises now because the compromised credentials are still actively traded and used in credential stuffing attacks. Attackers leverage these older dumps, combined with automated tools, to attempt to gain unauthorized access to a wide range of online accounts. The WeHeartIt breach serves as a reminder that data breaches have a long tail, and organizations must implement robust account security measures, including multi-factor authentication and password monitoring, to protect against credential reuse.
- Total records exposed: 6,408,496
- Types of data included: Email Address, Username, Password Hash
- Sensitive content types: None specifically (but PII inferred through email addresses)
- Source structure: Not specified, likely a database export.
- Leak location(s): Various breach forums and Telegram channels (observed in 2023-2024)
- Date of first appearance: November 2013 (breach), October 2017 (public disclosure)
External Context & Supporting Evidence
The WeHeartIt breach was widely reported in 2017 after its addition to "Have I Been Pwned?". News outlets like TechCrunch covered the incident, highlighting the delayed discovery and the use of weak hashing algorithms. Analysis of dark web marketplaces and Telegram channels reveals that the WeHeartIt data is frequently bundled with other older breaches, often marketed as a comprehensive credential database for password spraying campaigns. One Telegram post observed in January 2024 advertised "2013-2016 DUMPS - 100M+ CREDENTIALS" and included the WeHeartIt data as part of the package.
Breach Breakdown
6,408,496 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds