Data leak

Dailymotion Data Breach β€” 85.2M Email Addresses and Hashed Passwords

πŸ“… 2016-10-20 🏒 Dailymotion (French video-sharing platform, owned by Vivendi)
Primary Source β†—

Incident Details

On December 6, 2016, data breach tracking service LeakedSource reported that a dataset containing 85.2 million Dailymotion user records had been offered for sale and contained data from a breach believed to have occurred on or around October 20, 2016. The dataset contained email addresses for all 85.2 million records, and approximately 18.3 million of those records also included bcrypt-hashed passwords. The remaining accounts did not have passwords in the dataset, suggesting those users had registered via social login (Facebook, Google, etc.) rather than using a Dailymotion-native password. Dailymotion acknowledged the breach and began resetting passwords for affected users. The company stated it had strengthened its security systems following discovery. The precise attack vector was not disclosed. At the time, Dailymotion was one of the world’s largest video platforms, competing with YouTube and Vimeo, making this one of the larger media platform breaches of the era. The use of bcrypt for password hashing was considered a positive security practice compared to many contemporaneous breaches.

Technical Details

Initial Attack Vector
Database compromise of Dailymotion's user account database; the specific initial access vector was not publicly disclosed
Vendor / Product
Dailymotion (French video-sharing platform, owned by Vivendi)

Timeline

  1. 2016-10-20 Breach occurred
  2. 2016-12-06 Publicly disclosed
  3. 2016-12-06 Customers notified