Skip to content

Disqus

Disclosed Oct 6, 20178 years ago17,551,044 accountsUnverified

In October 2017, the blog commenting service Disqus announced they'd suffered a data breach . The breach dated back to July 2012 but wasn't identified until years later when the data finally surfaced. The breach contained over 17.5 million unique email addresses and usernames. Users who created logins on Disqus had salted SHA1 hashes of passwords whilst users who logged in via social providers only had references to those accounts.

What is known

People affected17,551,044 (accounts in the leaked data, per Have I Been Pwned)
DisclosedOct 6, 2017
HappenedJul 1, 2012
AttackNot stated
Data exposedEmails, Passwords
SectorTech
StatusUnverified: not yet confirmed by an official notice, a filing or the organization
Check your emailHave I Been Pwned

Sources

Source
Have I Been Pwned: Disqushaveibeenpwned.com · Aggregator

Notices filed

WhereFiledPeople
Have I Been Pwnedaccounts in the dataOct 6, 201717,551,044
History of this record
  • 2026-09-25 · added · backfill source

First seen 2026-09-25 (Have I Been Pwned). Record counts are as reported. Not legal advice.

Everything about Disqus

New breaches by email

Wednesdays, only in weeks with newly disclosed breaches, the largest first.

Double opt-in. Unsubscribe any time.