Skip to content

Drupal.org

Disclosed May 29, 201313 years ago1,000,000 affectedUnverified

Hack of Drupal.org forces password reset for nearly 1 million accounts

Attackers exploited a vulnerability in third party software on Drupal.org and accessed user data including password data, forcing resets for almost one million accounts.

What is known

People affected1,000,000 (as reported by the organization)
DisclosedMay 29, 2013
AttackHacking
Data exposedCredentials and tokens, Passwords
SectorTech · US
StatusUnverified: not yet confirmed by an official notice, a filing or the organization

Sources

Notices filed

WhereFiledPeople
ResearchtotalMay 29, 20131,000,000
History of this record
  • 2026-09-25 · added · seed source

First seen 2026-09-25 (Research). Record counts are as reported. Not legal advice.

Everything about Drupal.org

New breaches by email

Wednesdays, only in weeks with newly disclosed breaches, the largest first.

Double opt-in. Unsubscribe any time.