LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

Recent Breaches › ClixSense Data Breach (2016)

CRITICAL severityConfirmedHow we verify

ClixSense Data Breach (2016): What Was Exposed & What To Do

RBRecent Breaches Breach Intelligence·September 4, 2016

SourceBreach data provided in part by Have I Been Pwned, used under CC BY 4.0.

ClixSense Data Breach (2016)

Reported September 4, 2016. Approximately 2.4M people affected.

CRITICAL
Severity
2.4M
People affected
12
Data types exposed
September 4, 2016
Disclosed
ShareXLinkedInFacebookRedditWhatsAppTelegram

The ClixSense Data Breach (2016) (reported September 4, 2016) exposed Account balances, Dates of birth, Email addresses and Genders belonging to roughly 2.4M people. If you have an account with them, your information may now be circulating on the open web and with data brokers. Here’s exactly what happened, how to check if you were affected, and what to do next.

Severity & verification
CRITICAL severityConfirmed
Account credentials exposed.
Corroborated by an official disclosure or a verified breach feed.
Was your email in the ClixSense Data Breach (2016) breach?
2.4M accounts were exposed here. See if yours is one — and every other breach it’s in. 15-sec check, no card.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

In September 2016, the paid-to-click site ClixSense suffered a data breach that exposed records belonging to 2.4 million subscribers. The compromised data was posted online, with the actors responsible stating that the published material formed only a subset of a larger collection totalling 6.6 million records. The breach was reported on 4 September 2016. Public information on the method of intrusion, the precise date of access, or the full scope of any additional records remains limited to the attackers’ claims.

Inside the incident

The published data set contained names, physical addresses, email addresses, IP addresses, genders, dates of birth, account balances, payment histories, and passwords stored in plain text. No further technical details about how the data was obtained have been confirmed in public reporting.

How a breach like this happens

Incidents involving the exposure of user account data commonly begin with unauthorised access to an organisation’s systems, whether through compromised credentials, unpatched software, or misconfigured databases. Once inside, an actor can copy files containing personal and authentication information and later publish or sell the material. The presence of plain-text passwords indicates that stored credentials were not protected by hashing or encryption at the time of the incident.

About ClixSense

ClixSense operated as a paid-to-click platform where users completed surveys and other tasks in exchange for small payments. Services of this type maintain accounts that record personal identifiers, contact details, demographic information, and financial transaction histories to manage rewards and compliance. A breach at such a site therefore places at risk both the personal profiles and the payment-related records of its user base.

The information in question

The records posted online included account balances, dates of birth, email addresses, genders, IP addresses, names, passwords, and payment histories. The exact contents of any additional records beyond the published 2.4 million have not been independently verified.

What's at stake

Plain-text passwords increase the chance that affected accounts could be accessed on other sites where users reused the same credentials. Email addresses combined with names and dates of birth can facilitate targeted phishing or account-recovery attempts. Payment histories and account balances may reveal patterns of online activity that some individuals prefer to keep private. For the organisation, the incident highlights the long-term consequences of storing authentication data without additional protective measures.

What to do if you're exposed

Change the password on the affected account and on any other services that used the same or similar credentials. Enable multi-factor authentication where available and review recent account activity for signs of unauthorised use. Individuals can also run a free exposure scan of their email address against known breach data sets to check for further appearances of their information.

AICompiled with AI assistance from public sources and published under our editorial standards.

Editorial & sourcing policy
Recent Breaches is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data, and we do not hold the data claimed in leak-site listings. Incidents are compiled from publicly accessible sources and threat-intelligence platforms and are reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — write to support@galaxywarden.com or press@recentbreaches.com.
Check if you’re exposed →

How this breach connects

Company

Method

CompanyClixSense security record
73/100
DoxxScan™ · Moderate doxx risk
C- 64Below-average record

1 reported incident on record.

See ClixSense’s full breach history →

More recent breaches

Ethereum Data Breach (2016)December 16, 2016Anti Public Combo List Data Breach (2016)December 16, 2016PayAsUGym Data Breach (2016)December 15, 2016MrExcel Data Breach (2016)December 5, 2016

Latest breaches

Read GalaxyWarden’s full analysis of the ClixSense Data Breach (2016) →

Verified breach. Breach data provided in part by Have I Been Pwned, used under CC BY 4.0.

Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.

Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.

ShareXLinkedInFacebookRedditWhatsAppTelegram