Gravatar data breach (2020) — what was exposed and what to do
We publish these pages from public notices and reporting so you can understand what was exposed. Everything here is already public. Always confirm with the organization named in your notice.
What happened
According to public breach records, the Gravatar data breach on October 3, 2020 is reported to have exposed the personal information of 113,990,759 accounts.
In October 2020, a security researcher published a technique for scraping large volumes of data from Gravatar, the service for providing globally unique avatars . 167 million names, usernames and MD5 hashes of email addresses used to reference users' avatars were subsequently scraped and distributed within the hacking community. 114 million of the MD5 hashes were cracked and distributed alongside the source hash, thus disclosing the original email address and accompanying data. Following the impacted email addresses being searchable in HIBP, Gravatar release an FAQ detailing the incident.
Passwords in this breach were reportedly stored as MD5 hashes.
In October 2020, a security researcher published a technique for scraping large volumes of profile data from Gravatar, the globally-recognized-avatar service: because Gravatar assigned user profiles sequentially and applied virtually no rate limiting, profiles could be enumerated and harvested in numerical order at scale. Roughly 167 million names, usernames, and MD5 hashes of email addresses were scraped and circulated; about 114 million of those MD5 hashes were subsequently cracked and distributed alongside the source hashes, disclosing the original email addresses. What made it notable is that the exposure stemmed from how publicly-reachable profile data could be systematically enumerated rather than from a server intrusion, and no passwords were reported as exposed. In October 2020, a security researcher published a technique for scraping large volumes of profile data from Gravatar, the globally-recognized-avatar service: because Gravatar assigned user profiles sequentially and applied virtually no rate limiting, profiles could be enumerated and harvested in numerical order at scale. Roughly 167 million names, usernames, and MD5 hashes of email addresses were scraped and circulated, and about 114 million of those MD5 hashes were subsequently cracked and distributed alongside the source hashes, disclosing the original email addresses. What made it notable is that the exposure stemmed from how publicly-reachable profile data could be systematically enumerated rather than from a server intrusion, and no passwords were reported as exposed.
Sources
What data was exposed
The following types of personal data were compromised:
- Email addresses
- Names
- Usernames
Breach details
| Detail | Value |
|---|---|
| Breach name | Gravatar |
| Date | October 3, 2020 |
| Accounts affected | 113,990,759 |
| Domain | gravatar.com |
This summary is compiled from public breach-notification data and known leak databases. Figures reflect what those sources report and may be revised as more is learned. If something here looks wrong or you think your information is involved, contact our support team.
We report breaches as a factual record to help people check their exposure. Inclusion here is not an allegation of wrongdoing or negligence by Gravatar; it reflects a publicly reported security incident.
What to do now
Based on the data exposed in this breach, here are the steps you should take:
- Treat your Gravatar-linked email address as publicly known and tied to your name and username — be alert for targeted phishing and spoofed messages that reference these real details to appear legitimate.
- Because emails were leaked alongside names and usernames, watch for credential-stuffing attempts on accounts that reuse this email; ensure each important account uses a unique password and enable two-factor authentication.
- Avoid clicking links or attachments in unexpected emails that address you by your real name, and verify any account or security notice by navigating to the service directly rather than via emailed links.
- Consider using email aliases or filtering for the exposed address to contain spam and reduce the impact of being included in future combolists.
What to do after a breach
- A company emailed me about a breach: what should I do?
- Dark web data versus data brokers
- What to do after a data breach
A free Delist scan checks open-web exposure we support: people-search sites, public records, data brokers, and breach-source signals. Signals are not live listings, and this is not removing you from a dump, a DMV database, or a vendor's private ID store.
More breaches
Free personal data exposure scan
We search the open web for your personal data and show what’s exposed. The scan is free. Removal and monitoring require a paid plan.