Don’t do SECURITY. Do business SECURELY.

Hackers leak Gawker Media database of 1.3 million user accounts

A group called Gnosis breached Gawker Media and published around 1.3 million user account records, exposing weak password practices.

Hackers calling themselves Gnosis breached Gawker Media, publisher of sites including Gizmodo and Lifehacker, and released a database of around 1.3 million user accounts. The dump was shared publicly via a torrent file, making it easy for anyone to download.

What happened

  • The leaked data included commenters’ usernames, email addresses, and hashed passwords.
  • The attackers also published internal chat logs and some staff credentials, and said they had targeted Gawker in retaliation for its comments about 4chan.
  • Gawker apologised and urged users to change their passwords on Gawker and on any other sites where they had reused them.
  • Hijacked accounts on other services were soon used to spread spam, illustrating the risk of password reuse.

Why it mattered

The breach became a widely cited case study in weak password storage and reuse, and many sites forced password resets after checking the leaked list against their own users.

Lessons for organisations

Store passwords with modern, salted hashing algorithms, enforce MFA for staff tools, and encourage users to avoid reusing passwords. Monitoring for leaked credentials, and forcing resets when matches appear, helps catch reuse before attackers exploit it.

Sources: Help Net Security, Forbes

Part of our Top stories archive of headline-making events in information security, privacy, and AI. If you would like help applying the lessons to your organisation, contact us.

Get our weekly insights by emailA free weekly threat and vulnerability round-up with our threat log spreadsheet, plus legal, regulatory, standards, and AI updates.
Subscribe free

More insights