Artists&Clients Data Breach (2025): What Was Exposed & What To Do
SourceBreach data provided in part by Have I Been Pwned, used under CC BY 4.0.
Artists&Clients disclosed a data breach on 31 August 2025 that exposed the email addresses, IP addresses, passwords, and usernames of 95,000 users. Anyone with an account on the platform should check their email or the breach-notification channels for instructions and change any reused passwords immediately.
In the broader landscape of 2025 cyber threats, marketplace platforms that handle creative freelancers and client connections have become recurring targets for groups seeking both ransom payments and public data dumps. These incidents often involve claims of stolen user databases that surface on leak sites after failed negotiations, adding to a steady stream of exposures affecting tens of thousands of individuals at a time.
Artists&Clients, described as a marketplace connecting artists to prospective clients, was reported on August 31, 2025, as having suffered a data breach involving a US$50k ransom demand. The group known as lunalock has been linked to the incident through its claims; the data was subsequently leaked publicly and is said to cover 95,000 people. Exact method and initial intrusion timing remain undisclosed in available reporting.
Breaking down the breach
According to the reported summary, Artists&Clients experienced a data breach in August 2025. A ransom demand of US$50k followed. The data was later leaked publicly. Public detail confirms that the exposed set included 95k unique email addresses alongside usernames, IP addresses and bcrypt password hashes. No further technical indicators—such as the initial access vector, duration of unauthorized access, or confirmation of how the ransom demand was delivered—have been disclosed. The attribution rests on lunalock’s leak-site listing of the victim, which stands as an unverified claim rather than independently confirmed responsibility.
Who is lunalock?
Lunalock operates as a threat actor that publicly lists alleged victims on leak sites, typically after demanding payment to withhold stolen data. Like other groups in this category, it is known for combining data theft with ransom pressure and subsequent public dumps when negotiations fail. Well-documented patterns for such actors include targeting online platforms that store user credentials and contact details, then advertising the haul to increase leverage. No additional claims by lunalock specifically about Artists&Clients—beyond the listing itself—are part of the established public record for this incident. The group’s involvement here should therefore be treated as its own assertion pending further verification.
About Artists&Clients
Artists&Clients functions as an online marketplace that connects artists with prospective clients seeking commissioned work. Platforms of this type commonly maintain user accounts for freelancers and buyers, store project-related communications, and process or retain login credentials to enable ongoing transactions. A breach at such a service is consequential because the user base often includes independent creators whose professional identities, contact channels and account security are tightly linked to their livelihoods. Exposure can disrupt trust in the marketplace itself and create secondary risks for both artists and clients who rely on it for work.
The information in question
The facts name the exposed data types as email addresses, IP addresses, passwords and usernames. More precisely, the leaked material is reported to contain 95k unique email addresses together with usernames, IP addresses and bcrypt password hashes. Organisations in this sector typically also hold profile details, message histories or payment-related metadata, yet those categories are not confirmed as part of this incident. The exact full contents beyond the named fields remain limited to what has been publicly described; no broader inventory has been disclosed.
The real-world impact
For the approximately 95,000 affected individuals, the combination of email addresses, usernames and bcrypt password hashes creates concrete risks of credential-stuffing attacks against other services where the same password may have been reused. IP addresses can assist in correlating activity or refining targeted phishing. Artists and clients may face unsolicited contact, account takeover attempts or reputational friction if their professional handles appear in the dump. For Artists&Clients itself, the public leak after a US$50k ransom demand can erode user confidence and invite regulatory or contractual scrutiny, though no specific downstream consequences have been detailed in the available facts. The incident underscores how marketplace credentials, once hashed but still exposed, remain valuable to attackers even without plaintext passwords.
If your data was in this breach
If you used Artists&Clients, treat the reported exposure as a prompt for immediate hygiene rather than panic. Practical first steps include:
- Change the password on your Artists&Clients account and on any other site where you reused the same or a similar password.
- Enable multi-factor authentication wherever it is offered, prioritising email and financial accounts.
- Monitor the email address associated with the platform for unusual login alerts or phishing messages that reference the marketplace.
- Review recent account activity for unrecognised sessions or IP addresses.
- Consider placing fraud alerts with credit bureaus if you also stored payment details on the service, even though payment data itself is not named in this breach.
Readers can run a free exposure scan of their email address to check whether their information has already surfaced in known breach data sets. Public detail on this incident remains limited to the points above; further official statements from the organisation would be needed to confirm additional scope or remediation measures.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
Under Armour Data Breach (2025)Ralph Lauren Data Breach (2026)Madison Square Garden Sports Data Breach (2026)7-Eleven Data Breach (2026)Latest breaches
Read GalaxyWarden’s full analysis of the Artists&Clients Data Breach (2025) →
Verified breach. Breach data provided in part by Have I Been Pwned, used under CC BY 4.0.
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.