LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

Recent Breaches › 500px Data Breach (2018)

CRITICAL severityConfirmedHow we verify

500px Data Breach (2018): What Was Exposed & What To Do

RBRecent Breaches Breach Intelligence·July 5, 2018

SourceBreach data provided in part by Have I Been Pwned, used under CC BY 4.0.

500px Data Breach (2018)

Reported July 5, 2018. Approximately 14.9M people affected.

CRITICAL
Severity
14.9M
People affected
7
Data types exposed
July 5, 2018
Disclosed
ShareXLinkedInFacebookRedditWhatsAppTelegram

The 500px Data Breach (2018) (reported July 5, 2018) exposed Dates of birth, Email addresses, Genders and Geographic locations belonging to roughly 14.9M people. If you have an account with them, your information may now be circulating on the open web and with data brokers. Here’s exactly what happened, how to check if you were affected, and what to do next.

Severity & verification
CRITICAL severityConfirmed
Account credentials exposed.
Corroborated by an official disclosure or a verified breach feed.
Was your email in the 500px Data Breach (2018) breach?
14.9M accounts were exposed here. See if yours is one — and every other breach it’s in. 15-sec check, no card.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

In mid-2018 the online photography platform 500px experienced a data breach that exposed records belonging to 14.9 million users. The incident came to public attention on 5 July 2018, when details of the compromise were first reported; the data later appeared on a dark-web marketplace in 2019 and began circulating more widely thereafter. The breach is notable because it involved a large volume of personal identifiers together with password hashes, raising questions about how such material can be reused or combined with other datasets.

What happened

The breach occurred sometime in mid-2018. Public reporting at the time stated that nearly 15 million unique email addresses were taken, along with names, usernames, genders, dates of birth, geographic locations and password hashes stored in either MD5 or bcrypt format. No official statement from 500px has disclosed the precise method of intrusion, the duration of unauthorised access or the total number of records ultimately exfiltrated. In 2019 the same dataset was listed for sale on a dark-web marketplace alongside other large breach collections; subsequent circulation made portions of the material available on various online forums.

How a breach like this happens

Incidents involving the extraction of user databases commonly begin with an attacker obtaining access to an organisation’s internal systems through stolen credentials, unpatched software or misconfigured storage. Once inside, the intruder can locate and copy tables that contain account information. Passwords are frequently stored as hashes rather than plain text; depending on the hashing method used, those hashes may later be subjected to offline attempts to recover the original passwords. The 500px case followed this general pattern, though the specific vector that allowed initial entry remains undisclosed.

500px and its sector

500px operates as a social platform for photographers, enabling users to upload, share and license images. Services of this type maintain accounts that link creative work to personal details so that users can be identified, contacted or verified. Because members often treat the platform as a professional portfolio, the stored records can include biographical information that users consider stable over time. A breach at such a service therefore affects both individual privacy and the integrity of professional networks built around the site.

The information in question

The exposed fields explicitly reported include email addresses, names, usernames, genders, dates of birth, geographic locations and password hashes. No further categories of data, such as payment details or private image metadata, have been confirmed in public accounts of the incident. Organisations that host user-generated content routinely collect profile information of this kind to support account creation, community features and compliance requirements; the exact scope of records taken from 500px has not been independently verified beyond the fields listed above.

What's at stake

Individuals whose records were included face the possibility that their email addresses and usernames can be linked to other online services, increasing the chance of targeted phishing or credential-stuffing attempts. Password hashes, even when not immediately reversible, can be tested against common passwords or reused across sites. Dates of birth and location data add context that may assist in identity-verification processes or social-engineering scenarios. For the organisation, the incident creates ongoing costs related to user notification, security remediation and potential regulatory scrutiny, while eroding trust among members who rely on the platform for professional exposure.

What to do if you're exposed

Anyone who used 500px should change the password on that account and on any other service where the same password or a close variant was reused. Enabling multi-factor authentication wherever available reduces the value of a leaked password hash. Monitoring email accounts for unexpected login attempts or password-reset messages provides an early indicator of misuse. Individuals can also run a free exposure scan of their email address against known breach datasets to determine whether their information appears in this or other publicly documented incidents.

AICompiled with AI assistance from public sources and published under our editorial standards.

Editorial & sourcing policy
Recent Breaches is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data, and we do not hold the data claimed in leak-site listings. Incidents are compiled from publicly accessible sources and threat-intelligence platforms and are reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — write to support@galaxywarden.com or press@recentbreaches.com.
Check if you’re exposed →

How this breach connects

Company

Method

Company500px security record
73/100
DoxxScan™ · Moderate doxx risk
C- 64Below-average record

1 reported incident on record.

See 500px’s full breach history →

More recent breaches

Società Italiana degli Autori ed Editori Data Breach (2018)November 3, 20188fit Data Breach (2018)July 1, 2018Estonian Citizens (via Estonian Cybercrime Bureau) Data Breach (2018)June 7, 20182,844 Separate Data Breaches Data Breach (2018)February 19, 2018

Latest breaches

Read GalaxyWarden’s full analysis of the 500px Data Breach (2018) →

Verified breach. Breach data provided in part by Have I Been Pwned, used under CC BY 4.0.

Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.

Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.

ShareXLinkedInFacebookRedditWhatsAppTelegram