LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

Recent Breaches › Artists&Clients Data Breach (2025)

HIGH severityConfirmedHow we verify

Artists&Clients Data Breach (2025): What Was Exposed & What To Do

RBRecent Breaches Breach Intelligence·August 31, 2025

SourceBreach data provided in part by Have I Been Pwned, used under CC BY 4.0.

Artists&Clients Data Breach (2025)

Reported August 31, 2025. Approximately 95K people affected.

HIGH
Severity
95K
People affected
4
Data types exposed
August 31, 2025
Disclosed
ShareXLinkedInFacebookRedditWhatsAppTelegram

Artists&Clients disclosed a data breach on 31 August 2025 that exposed the email addresses, IP addresses, passwords, and usernames of 95,000 users. Anyone with an account on the platform should check their email or the breach-notification channels for instructions and change any reused passwords immediately.

Severity & verification
HIGH severityConfirmed
Account credentials exposed.
Corroborated by an official disclosure or a verified breach feed.
Check your exposure
95K accounts were exposed here. We can’t confirm any single incident against the sources we search — but we can show you every leak and listing tied to your email. 15-sec check, no card.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

In the broader landscape of 2025 cyber threats, marketplace platforms that handle creative freelancers and client connections have become recurring targets for groups seeking both ransom payments and public data dumps. These incidents often involve claims of stolen user databases that surface on leak sites after failed negotiations, adding to a steady stream of exposures affecting tens of thousands of individuals at a time.

Artists&Clients, described as a marketplace connecting artists to prospective clients, was reported on August 31, 2025, as having suffered a data breach involving a US$50k ransom demand. The group known as lunalock has been linked to the incident through its claims; the data was subsequently leaked publicly and is said to cover 95,000 people. Exact method and initial intrusion timing remain undisclosed in available reporting.

Breaking down the breach

According to the reported summary, Artists&Clients experienced a data breach in August 2025. A ransom demand of US$50k followed. The data was later leaked publicly. Public detail confirms that the exposed set included 95k unique email addresses alongside usernames, IP addresses and bcrypt password hashes. No further technical indicators—such as the initial access vector, duration of unauthorized access, or confirmation of how the ransom demand was delivered—have been disclosed. The attribution rests on lunalock’s leak-site listing of the victim, which stands as an unverified claim rather than independently confirmed responsibility.

Who is lunalock?

Lunalock operates as a threat actor that publicly lists alleged victims on leak sites, typically after demanding payment to withhold stolen data. Like other groups in this category, it is known for combining data theft with ransom pressure and subsequent public dumps when negotiations fail. Well-documented patterns for such actors include targeting online platforms that store user credentials and contact details, then advertising the haul to increase leverage. No additional claims by lunalock specifically about Artists&Clients—beyond the listing itself—are part of the established public record for this incident. The group’s involvement here should therefore be treated as its own assertion pending further verification.

About Artists&Clients

Artists&Clients functions as an online marketplace that connects artists with prospective clients seeking commissioned work. Platforms of this type commonly maintain user accounts for freelancers and buyers, store project-related communications, and process or retain login credentials to enable ongoing transactions. A breach at such a service is consequential because the user base often includes independent creators whose professional identities, contact channels and account security are tightly linked to their livelihoods. Exposure can disrupt trust in the marketplace itself and create secondary risks for both artists and clients who rely on it for work.

The information in question

The facts name the exposed data types as email addresses, IP addresses, passwords and usernames. More precisely, the leaked material is reported to contain 95k unique email addresses together with usernames, IP addresses and bcrypt password hashes. Organisations in this sector typically also hold profile details, message histories or payment-related metadata, yet those categories are not confirmed as part of this incident. The exact full contents beyond the named fields remain limited to what has been publicly described; no broader inventory has been disclosed.

The real-world impact

For the approximately 95,000 affected individuals, the combination of email addresses, usernames and bcrypt password hashes creates concrete risks of credential-stuffing attacks against other services where the same password may have been reused. IP addresses can assist in correlating activity or refining targeted phishing. Artists and clients may face unsolicited contact, account takeover attempts or reputational friction if their professional handles appear in the dump. For Artists&Clients itself, the public leak after a US$50k ransom demand can erode user confidence and invite regulatory or contractual scrutiny, though no specific downstream consequences have been detailed in the available facts. The incident underscores how marketplace credentials, once hashed but still exposed, remain valuable to attackers even without plaintext passwords.

If your data was in this breach

If you used Artists&Clients, treat the reported exposure as a prompt for immediate hygiene rather than panic. Practical first steps include:

Readers can run a free exposure scan of their email address to check whether their information has already surfaced in known breach data sets. Public detail on this incident remains limited to the points above; further official statements from the organisation would be needed to confirm additional scope or remediation measures.

AICompiled with AI assistance from public sources and published under our editorial standards.

Editorial & sourcing policy
Recent Breaches is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data, and we do not hold the data claimed in leak-site listings. Incidents are compiled from publicly accessible sources and threat-intelligence platforms and are reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — write to support@galaxywarden.com or press@recentbreaches.com.
Check if you’re exposed →

How this breach connects

Company

Attributed to

Method

CompanyArtists&Clients security record
68/100
DoxxScan™ · Moderate doxx risk
C- 60Below-average record

1 reported incident on record.

See Artists&Clients’s full breach history →

More recent breaches

Under Armour Data Breach (2025)November 17, 2025Ralph Lauren Data Breach (2026)June 11, 2026Madison Square Garden Sports Data Breach (2026)June 5, 20267-Eleven Data Breach (2026)April 8, 2026

Latest breaches

Read GalaxyWarden’s full analysis of the Artists&Clients Data Breach (2025) →

Verified breach. Breach data provided in part by Have I Been Pwned, used under CC BY 4.0.

Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.

Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.

ShareXLinkedInFacebookRedditWhatsAppTelegram