FaceUP Data Breach (2013): What Was Exposed & What To Do
SourceBreach data provided in part by Have I Been Pwned, used under CC BY 4.0.
The FaceUP Data Breach (2013) (reported January 1, 2013) exposed Dates of birth, Email addresses, Genders and Names belonging to roughly 88K people. If you have an account with them, your information may now be circulating on the open web and with data brokers. Here’s exactly what happened, how to check if you were affected, and what to do next.
In 2013 the Danish social media platform FaceUP experienced a data breach that exposed information on approximately 88,000 individuals. The incident came to light on 1 January 2013 and involved email addresses, names, dates of birth, genders, phone numbers, usernames and passwords stored as unsalted MD5 hashes. FaceUP stated at the time that it had identified a SQL injection vulnerability and had forced password resets for affected accounts.
What happened
The breach occurred in 2013 and affected the Danish social media site FaceUP. Public records indicate that 87,000 unique email addresses were exposed together with associated personal details and credentials. The passwords were stored as unsalted MD5 hashes. When notified of the incident, the organisation reported that it had located a SQL injection vulnerability and had required password resets for the impacted users. No further technical details or exact timeline beyond the 2013 reporting date have been disclosed.
How a breach like this happens
SQL injection remains a common entry point for unauthorised access to web applications. An attacker submits specially crafted input that is interpreted as database commands rather than ordinary data, allowing retrieval or modification of records stored in the back-end system. Once inside the database, an attacker can copy tables containing user information. Passwords stored without a unique salt and with an outdated hashing algorithm such as MD5 can be processed offline at high speed, increasing the chance that some credentials may be recovered.
Who is FaceUP?
FaceUP operated as a social media platform based in Denmark. Services of this type collect and store account credentials along with profile information that users provide during registration and routine use. A breach at such a service is consequential because the data typically includes identifiers that remain stable over time and can be combined with other sources to build detailed profiles of individuals.
What was likely exposed
The records that have been reported as exposed include dates of birth, email addresses, genders, names, passwords, phone numbers and usernames. The passwords were stored as unsalted MD5 hashes. Organisations in this sector commonly retain additional fields such as account creation dates or login histories, yet the precise scope of the FaceUP dataset beyond the listed categories remains unconfirmed in public reporting.
The real-world impact
Individuals whose information appeared in the incident face the possibility that their email addresses and phone numbers may be used for targeted phishing or that recovered passwords may be tested against other accounts. Because dates of birth and names were also present, the data could assist in identity-verification processes at other services. For the organisation, the event highlighted the need to replace legacy password storage methods and to close injection flaws that allow bulk extraction of user records.
Were you affected?
Anyone who created an account on FaceUP around or before 2013 can check whether their email address appears in known breach datasets by using a free exposure scan service. If an account is confirmed as affected, the immediate steps are to change the password on any site where the same credential was reused and to enable multi-factor authentication where available. Monitoring email and phone accounts for unexpected activity provides an additional practical safeguard while the full extent of any downstream misuse remains unknown.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
Astropid Data Breach (2013)Torrent Invites Data Breach (2013)Pixel Federation Data Breach (2013)Vodafone Data Breach (2013)Latest breaches
Read GalaxyWarden’s full analysis of the FaceUP Data Breach (2013) →
Verified breach. Breach data provided in part by Have I Been Pwned, used under CC BY 4.0.
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.