Porn website hack leaks 'over 1m' passwords
YouPorn's Chat service gets hacked, leaking a load of login information.

Popular adult website YouPorn has been caught in an awkward position after users' account information was laid bare by hackers.
According to security blogger Anders Nilsson, the email addresses, passwords and birthdates of over one million users were made publicly accessible.
A Naked Security blog post claimed YouPorn - one of the top 100 most popular websites in the world - has been publishing users' data in a public fashion since 2007. These practices were blamed for the security breach.
While YouPorn has shut down the breached server, hackers are still sifting through the information and reposting it elsewhere online.
After the initial shock and embarrassment of this exposure, users now have to worry about the security of their online identity.
With users' email addresses and passwords now publicly accessible, it may be easy for hackers to use this information to break into users' email, Amazon, PayPal, and Facebook accounts, because many still use the same password for multiple accounts.
However, a YouPorn official blog post stated that, contrary to news reports, only YP Chat account information has been released.
Get the ITPro daily newsletter
Sign up today and you will receive a free copy of our Future Focus 2025 report - the leading guidance on AI, cybersecurity and other IT challenges as per 700+ senior executives
"The real focus of the recent news is YP Chat, an entirely separate service that was linked to from YouPorn.com," Brad Black, YouPorn vice president of operations, wrote in the blog post.
"The chat service is owned and operated by a third party and is in no way associated with YouPorn.com."
Black has assured that YouPorn has taken steps to prevent further damage and remedy the situation.
"As soon as we, at YouPorn.com, became aware of the issue we took immediate steps to block access to YP Chat entirely and a thorough investigation was launched to evaluate the scope of the issue," he said.
However, the release of passwords and email account information is still problematic for those who have used the same log-ins for both sites.
"The security of our users' information has always been and will always be of paramount importance to us and the fact that a third-party service provider's poor security practices could have such a negative impact on YouPorn users is disheartening to say the least," Black said.
-
Bigger salaries, more burnout: Is the CISO role in crisis?
In-depth CISOs are more stressed than ever before – but why is this and what can be done?
By Kate O'Flaherty Published
-
Cheap cyber crime kits can be bought on the dark web for less than $25
News Research from NordVPN shows phishing kits are now widely available on the dark web and via messaging apps like Telegram, and are often selling for less than $25.
By Emma Woollacott Published
-
Capita tells pension provider to 'assume' nearly 500,000 customers' data stolen
Capita told the pension provider to “work on the assumption” that data had been stolen
By Ross Kelly Published
-
Gumtree site code made personal data of users and sellers publicly accessible
News Anyone could scan the website's HTML code to reveal personal information belonging to users of the popular second-hand classified adverts website
By Connor Jones Published
-
Pizza chain exposed 100,000 employees' Social Security numbers
News Former and current staff at California Pizza Kitchen potentially burned by hackers
By Danny Bradbury Published
-
83% of critical infrastructure companies have experienced breaches in the last three years
News Survey finds security practices are weak if not non-existent in critical firms
By Rene Millman Published
-
Identity Automation launches credential breach monitoring service
News New monitoring solution adds to the firm’s flagship RapidIdentity platform
By Praharsha Anand Published
-
Neiman Marcus data breach hits 4.6 million customers
News The breach took place last year, but details have only now come to light
By Rene Millman Published
-
Indiana notifies 750,000 after COVID-19 tracing data accessed
News The state is following up to ensure no information was transferred to bad actors
By Rene Millman Published
-
Pearson fined $1 million for downplaying severity of 2018 breach
News The SEC found the London-based firm made “misleading statements and omissions” about the intrusion
By Rene Millman Published