Skip to content

Lumin PDF

Disclosed Sep 18, 20197 years ago15,453,048 accountsUnverified

In April 2019, the PDF management service Lumin PDF suffered a data breach . The breach wasn't publicly disclosed until September when 15.5M records of user data appeared for download on a popular hacking forum. The data had been left publicly exposed in a MongoDB instance after which Lumin PDF was allegedly been "contacted multiple times, but ignored all the queries". The exposed data included names, email addresses, genders, spoken language and either a bcrypt password hash or Google auth token.

What is known

People affected15,453,048 (accounts in the leaked data, per Have I Been Pwned)
DisclosedSep 18, 2019
HappenedApr 1, 2019
AttackHacking
Data exposedCredentials and tokens, Emails, Names, Passwords, Dates of birth
SectorTech
StatusUnverified: not yet confirmed by an official notice, a filing or the organization
Check your emailHave I Been Pwned

Sources

Source
Have I Been Pwned: Lumin PDFhaveibeenpwned.com · Aggregator

Notices filed

WhereFiledPeople
Have I Been Pwnedaccounts in the dataSep 18, 201915,453,048
History of this record
  • 2026-09-25 · added · backfill source

First seen 2026-09-25 (Have I Been Pwned). Record counts are as reported. Not legal advice.

Everything about Lumin PDF

New breaches by email

Wednesdays, only in weeks with newly disclosed breaches, the largest first.

Double opt-in. Unsubscribe any time.