(Image: Imgur)

Imgur, one of the world's most visited websites, has confirmed a hack dating back to 2014.

Imgur confirms email addresses, passwords stolen in 2014 hack

The hackers stole email addresses and passwords.

By  for Zero Day | 

The company told ZDNet that hackers stole 1.7 million email addresses and passwords, scrambled with the SHA-256 algorithm, which has been passed over in recent years in favor of stronger password scramblers.

Imgur said the breach didn't include personal information because the site has "never asked" for real names, addresses, or phone numbers.

The stolen accounts represent a fraction of Imgur's 150 million monthly users.

The hack went unnoticed for four years until the stolen data was sent to Troy Hunt, who runs data breach notification service Have I Been Pwned. Hunt informed the company on Thursday, a US national holiday observing Thanksgiving, when most businesses are closed.

A day later, the company started resetting the passwords of affected accounts, and published a public disclosure alerting users of the breach.

Hunt praised the company's efforts for its quick response.

"I disclosed this incident to Imgur late in the day in the midst of the US Thanksgiving holidays," said Hunt. "That they could pick this up immediately, protect impacted accounts, notify individuals and prepare public statements in less than 24 hours is absolutely exemplary."

 

It's the latest historical hack from a long list of companies that have this year revealed security breaches dating back to the turn of the decade, including DisqusLinkedInMySpace, and Yahoo.

Imgur's chief operating officer Roy Sehgal said the company was "still investigating" how the account information was compromised, but said that site security had improved since the breach.

The company said it has changed its password hashing to bcrypt, a much stronger password scrambler, last year. But anyone who uses the same Imgur email address and password combination on other sites should also change those passwords.

Sehgal also said in an email that the company, based in California, plans to disclose the data breach to the state's attorney general, law enforcement, and other relevant government agencies.

According to Hunt, 60 percent of email addresses were already in Have I Been Pwned's database of more than 4.8 billion records.

Contact me securely

Zack Whittaker can be reached securely on Signal and WhatsApp at 646-755–8849, and his PGP fingerprint for email is: 4D0E 92F2 E36A EC51 DAAE 5D97 CB8C 15FA EB6C EEA5.

Read More

ZDNET INVESTIGATIONS