- Total Records2,798,911
- Unique Emails2,331,404
- Unique Usernames2,768,422
Elanic Data Breach Exposed 2.8 Million User Records in 2020
Elanic, an online Indian fashion marketplace, experienced a data breach in January 2020 that resulted in the exposure of nearly 2.8 million user records. The incident traces back to a test server, which held user account details including email addresses, usernames, geographic locations, phone numbers, and associated social media information. Out of all records, about 2.3 million unique email addresses were present. Although Elanic verified that the leaked data was legitimate, they reportedly decided against directly informing users, as they deemed the exposed information to be outdated.
What Happened in the Elanic Breach?
In early January 2020, unauthorized access to Elanic's test server led to the public leaking of millions of user records. Security researchers discovered the breach and confirmed that data belonging to real Elanic customers had become available online. The exposed information covered a broad swath of the platform's user base, reflecting both historic and potentially current data at the time of the breach.
What Data Was Exposed?
- Email addresses
- Usernames
- Phone numbers
- Geographic locations
- Linked social media information
The data did not include sensitive payment or password information, but the nature of the leaked information could still be valuable for attackers engaged in targeted phishing or account impersonation.
Scope and Impact
The breach affected a total of 2,798,912 records from Elanic's platform, with 2.3 million of them tied to unique email addresses. This large number highlights the popularity of Elanic as a secondhand fashion marketplace in India during its years of peak activity.
Timeline of the Elanic Breach
- January 2020: Elanic's test server is accessed and user data is exposed online.
- After discovery: Security researchers notified Elanic of the breach.
- Elanic confirmed: The data was valid but categorized as old, deciding not to formally notify affected users.
Frequently Asked Questions
How many users were affected by the Elanic data breach?
Approximately 2.8 million user records were exposed, with just over 2.3 million unique email addresses among them.
What user data was included in the Elanic breach?
The breach exposed email addresses, usernames, phone numbers, geographic location details, and associated social media information belonging to Elanic users.
What caused the Elanic breach to happen?
The root cause was unauthorized access to a test server containing real user data. This led to the data being publicly accessible and eventually acquired by unauthorized parties.
How can I check if I'm in the Elanic breach?
You can check if your information was part of the Elanic breach by utilizing the DeHashed search engine.