us

216.73.217.135

Back
News

8.3 million users affected in ‘Freepik data breach’

8.3 million users affected in ‘Freepik data breach’
R Richard M. AUGUST 24, 2020 1 minute read

Freepik, a free photo and graphics site, has disclosed a major data breach that affected nearly 8.3 million users on their site. The company officially revealed data breach after users started protesting on social media about receiving ‘shady emails’ in their inboxes regarding the breach.

 

On Thursday, ZDNET reached out to Freepik and company officially disclosed a data breach on Friday (August 21, 2020) confirming the authenticity of emails being sent to registered users to notify about the breach.

The security breach occurred as a result of SQL injection vulnerability to access one of the databases having user data, stated the company’s official statement. According to Freepik, the hacker gathered usernames and passwords of the oldest registered users on Flaticon and Freepik websites.  

Though Freepik didn’t issue any formal statement regarding when the breach took place, however, they informed the authorities as soon as they detected the breach and began the investigations about compromised data.

Moreover, in their statement, Feepik stated that for some users the hacker took only user emails since not all accounts had passwords associated with them. As per them, 4.5 million such users used third-party logins (Facebook, Twitter, Google, etc.) to register and log into their accounts. Freepik said,

“For the remaining 3.77M users the attacker got their email address and a hash of their password”

The company announced they are now in process of informing all the affected user about the breach in personalized emails, notifying what was compromised.

Disclaimer: The views and opinions expressed on this webpage or weblink are those of the author only, and are not necessarily the views or opinions of Shufti Pro Limited. The material and information on this weblink is solely for general information purposes. You should not rely upon the material or information on the website as a basis for making any business or legal decision.

While we endeavor to keep the information up-to-date and/or correct, we make no representations or warranties of any kind, express or implied, or for any purpose about the completeness, accuracy, reliability, suitability, or availability of the contents or information herein. Any reliance on its content is thus entirely at your own risk.

For the avoidance of doubt, Shufti Pro Limited will not be liable for any false, inaccurate, inappropriate, or incomplete information presented herein, and all liabilities with respect to actions taken, or not taken, based on the contents or information herein, or for any loss sustained by you as a consequence are hereby expressly disclaimed by us.

Share you link

Bring your voice

Bring Your Voice.

The community for every hand that writes and every voice that speaks against fraud.

Join Community

Pitch a piece and get a verified byline in the Media room.

“Industry Partnerships That Create Real Value”

Join Shufti’s partnership network to expand your connections, collaborate with industry leaders, and unlock new opportunities.

Pitch a piece and get a verified byline in the Media room.

Partnership Inquiries?
Email us at [email protected]

iBeta Level 1 — ISO 30107-3 Compliant iBeta Level 2 — ISO 30107-3 Compliant iBeta Level 3 — ISO 30107-3 Compliant PCI DSS SOC 2 Type 2 GDPR GDPR Fundamentals — Quality Guild ISO 27001:2022 KJM Age Verification CCPA / CPRA Cyber Essentials Cyber Essentials Plus
Copyright © 2026 Shufti. All rights reserved.