Wattpad data breach (2020): what was exposed and what to do
We publish these pages from public notices and reporting so you can understand what was exposed. Everything here is already public. Always confirm with the organization named in your notice.
What happened
Wattpad's June 2020 breach exposed personal data from its storytelling community. Have I Been Pwned (HIBP) lists approximately 268.8 million affected email addresses and added the incident on July 19, 2020. The data was initially sold and later circulated publicly.[1]
That figure describes the breach dataset, not a count of current Wattpad users. This article cannot establish whether a particular person's account was included.
What the sources say about passwords
HIBP describes bcrypt password hashes.[1] BleepingComputer reported seeing both bcrypt and SHA-256 hashes in samples, while noting that it had not independently authenticated the entire database. Its July 20 update reported Wattpad's precautionary password reset.[2] These accounts differ in scope; neither supports treating every exposed password as having the same protection.
Sources
- Have I Been Pwned: Wattpad breach record
- BleepingComputer: Wattpad breach reporting and July 20, 2020 update
- FTC: How to recognize and avoid phishing scams
Sources checked September 26, 2026. This is a correction of the 2020 incident summary, not a report of a new breach.
What data was exposed
HIBP lists these categories:[1]
- Names, usernames, bios, and genders
- Email addresses and dates of birth
- IP addresses and geographic locations
- Passwords
- Social media profiles and personal website URLs
Breach details
| Detail | Value |
|---|---|
| Breach name | Wattpad |
| Incident period | June 2020 |
| Affected email addresses | Approximately 268.8 million, according to HIBP |
| Added to HIBP | July 19, 2020 |
| Domain | wattpad.com |
This summary is compiled from public breach-notification data and known leak databases. Figures reflect what those sources report and may be revised as more is learned. If something here looks wrong or you think your personal data is involved, contact our support team.
We report breaches as a factual record to help people check their exposure. Inclusion here is not an allegation of wrongdoing or negligence by Wattpad; it reflects a publicly reported security incident.
What to do now
- Replace any still-used affected password. If you have not changed the password used at the time of this breach, change it on Wattpad and anywhere else you reused it. Use a different password for each account.[1]
- Enable two-factor authentication where supported. Check your email provider and other important accounts for available security settings. This recommendation does not assume Wattpad offers a particular 2FA setting.[1]
- Treat unexpected messages cautiously. Open the service directly instead of following a password-reset or account-warning link in a message. Familiar personal details do not prove a message is genuine.[3]
For a broader checklist, read what to do in the first 48 hours after a data breach.
What to do after a breach
- A company emailed me about a breach: what should I do?
- Dark web data versus data brokers
- What to do after a data breach
A free Delist scan checks open-web exposure we support: people-search sites, public records, data brokers, and breach-source signals. Signals are not live listings, and this is not removing you from a dump, a DMV database, or a vendor's private ID store.
More breaches
Free personal data exposure scan
We search the open web for your personal data and show what’s exposed. The scan is free. Removal and monitoring require a paid plan.