[German]The Pinterest service has (probably) suffered a major data leak affecting its registered users. While it's not confirmed, security researchers from Surfshark have looked at the details and found that the USA and France are the most affected countries among the 6 million affected users. Overall are 6 million user accounts affected.
Advertising
What is Pinterest?
Pinterest is an online service founded in March 2010 that primarily provides a pinboard for graphics and photographs. The name is derived from pinning (to pin) and interest (interest). Users can pin their pictures or graphics to their pinboard online and make them accessible to third parties. The service and app also offer an optional social network and a visual search engine. In 2021, over 400 million users were registered on Pinterest – there are now said to be over 518 million monthly active users.
Data leak with 6 million people affected reported
On July 15, 2024, Cyber-Security-News reported in this article about a possible data leak at Pinterest. A hacker by the name of "Tchao1337" allegedly has a database with 60 million records containing Pinterest user data. The hacker offered the database in an underground data leak forum and probably published some information and data records.
It is said that the leaked database contains 6 million records of users. The compressed database file has a file size of 1.59 gigabytes. While the full extent of the leaked information is not known, the leaked data includes email addresses, usernames, user IDs and IP addresses.
The source is the website cyberpress.org, which reported here. The hacker states that a third party is selling part of the database. Contacted by Cyber-Security-News, a Pinterest spokesperson stated that "an investigation has revealed no evidence that the system or user data has been compromised". However, users should change their login details and be wary of phishing.
Breakdown of the data
Security experts from the VPN provider Surfshark have looked at the data (even if the Pinterest hack is unconfirmed) and sent me the following information:
Advertising
- There were (allegedly) 6,837,667 IP addresses of Pinterest users published.
- The vast majority of the IP addresses (6,835,264) are assigned to an email address (user login address).
- A total of 13.7 million data points (user accounts) were disclosed in the (possible) data breach at Pinterest.
There are also interesting insights into the countries affected. This time, the USA is not prominently at the forefront – as the following breakdown shows. The data can be accessed via the following interactive map.
Pinterest data leak, source:Surfshark
- France is the most affected country, with 1.97 million emails affected and a total of 3.9 million data points exposed. French data accounts for 28.8% of all leaked Pinterest data.
- The USA follows with 1.91 million affected emails and the same number of IP addresses. American user data accounts for 27.9% of all published data points.
- India is in third place with 264,000 Indian emails and IP addresses exposed. China ranks fourth in terms of leaked user accounts with 216,000 compromised data points from individuals.
- The United Kingdom ranks 5th (216K affected individuals), Brazil 6th (145K), Micronesia 7th (126K), followed by Germany (113K), Japan (109K) and Italy (80K).
Surfshark has published the details in a table on Google Docs. Data from almost 18 billion user accounts worldwide has now been affected by data leaks.
Advertising