Famm Data Breach (2020): What Was Exposed & What To Do
SourceBreach data provided in part by Have I Been Pwned, used under CC BY 4.0.
The Famm Data Breach (2020) (reported October 8, 2020) exposed Dates of birth, Email addresses, Genders and Names belonging to roughly 535K people. If you have an account with them, your information may now be circulating on the open web and with data brokers. Here’s exactly what happened, how to check if you were affected, and what to do next.
Inside the incident
The breach affected Famm, a platform focused on family photography services in Japan. Public reporting indicates that 1.3 million customer records were exposed, encompassing 535,000 unique email addresses along with associated names, dates of birth, genders, and passwords stored as SHA-256 hashes. The date of the intrusion itself remains undisclosed, as does the method by which access was obtained. No further technical details about the event have been confirmed in available records.
How a breach like this happens
Incidents involving the exposure of user account data often begin with unauthorized access to a company’s systems. This can occur through exploitation of software vulnerabilities, compromised credentials at the organization, or misconfigured databases that allow external retrieval of stored information. Once access is gained, attackers may copy files containing account details before the activity is detected. Passwords stored only as hashes, rather than in plain text, still require additional effort to reverse, but the presence of other identifying fields increases the overall value of the dataset to anyone who obtains it.
About Famm
Famm operates as a Japanese service centered on family photography and photo sharing. Organizations in this sector maintain user accounts to enable features such as photo uploads, storage, and distribution among family members. These accounts routinely collect basic profile information to support registration and service delivery. A breach at such a service is consequential because the data held is tied directly to individuals’ personal lives and often includes details that persist over time, such as dates of birth.
What data was at risk
The records exposed in the incident contained the following categories of information:
- Dates of birth
- Email addresses
- Genders
- Names
- Passwords stored as SHA-256 hashes
Exact confirmation of every field present in the full 1.3 million records has not been provided beyond these named types.
Why it matters
For individuals whose information appeared in the exposed records, the combination of email addresses with names and dates of birth creates opportunities for targeted phishing or account takeover attempts on other services where the same credentials may have been reused. Hashed passwords add a layer of protection but do not eliminate risk if users employed common passwords or if the hashes can be processed offline. For the organization, the event highlights the long-term sensitivity of customer profile data collected for routine service functions.
What to do if you're exposed
Individuals concerned about possible exposure should change passwords on the affected account and any other services where the same password was used. Enabling multi-factor authentication where available adds further protection. Monitoring email accounts for unusual activity is also advisable. Readers can run a free exposure scan of their email address to check whether their information has surfaced in known breach data.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
MEO Data Breach (2020)NetGalley Data Breach (2020)MMG Fusion Data Breach (2020)DriveSure Data Breach (2020)Latest breaches
Read GalaxyWarden’s full analysis of the Famm Data Breach (2020) →
Verified breach. Breach data provided in part by Have I Been Pwned, used under CC BY 4.0.
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.