LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

Recent Breaches › Houzz Data Breach (2018)

CRITICAL severityConfirmedHow we verify

Houzz Data Breach (2018): What Was Exposed & What To Do

RBRecent Breaches Breach Intelligence·May 23, 2018

SourceBreach data provided in part by Have I Been Pwned, used under CC BY 4.0.

Houzz Data Breach (2018)

Reported May 23, 2018. Approximately 48.9M people affected.

CRITICAL
Severity
48.9M
People affected
7
Data types exposed
May 23, 2018
Disclosed
ShareXLinkedInFacebookRedditWhatsAppTelegram

The Houzz Data Breach (2018) (reported May 23, 2018) exposed Email addresses, Geographic locations, IP addresses and Names belonging to roughly 48.9M people. If you have an account with them, your information may now be circulating on the open web and with data brokers. Here’s exactly what happened, how to check if you were affected, and what to do next.

Severity & verification
CRITICAL severityConfirmed
Account credentials exposed.
Corroborated by an official disclosure or a verified breach feed.
Was your email in the Houzz Data Breach (2018) breach?
48.9M accounts were exposed here. See if yours is one — and every other breach it’s in. 15-sec check, no card.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

In mid-2018 the housing design platform Houzz experienced a data breach that exposed records belonging to 48.9 million users. The company became aware of the incident later that year and notified affected members in February 2019. The data, which included email addresses along with names, geographic locations, IP addresses, usernames, salted password hashes and links to social media profiles used for authentication, later appeared in collections shared with the Have I Been Pwned service. The incident illustrates the continuing exposure of large consumer-service databases even as organisations improve detection and disclosure practices. With nearly 49 million unique email addresses involved, the event stands among the larger user-account breaches recorded that year.

Breaking down the breach

The breach was first reported publicly on 23 May 2018. At that time the scale was stated as 48.9 million affected individuals. The exposed records contained email addresses, names, geographic locations, IP addresses, usernames, salted hashes of passwords and references to social media profiles employed for login. No further technical details on the method of access or the precise date range of the intrusion have been released by the company. The dataset was supplied to breach-tracking services by the third-party site dehashed.com.

How a breach like this happens

Incidents involving consumer websites frequently begin with an attacker obtaining credentials or exploiting an application or database vulnerability that grants access to stored user records. Once inside, an actor can copy tables that hold account identifiers, contact details and authentication material. Passwords are commonly stored as salted hashes rather than plain text, yet the hashes themselves remain useful for offline attempts at recovery. Data of this kind is often aggregated and later circulated among researchers or on public breach repositories, which is how the Houzz records reached Have I Been Pwned.

About Houzz

Houzz operates an online platform focused on home design, renovation and interior products. Users create accounts to browse projects, contact professionals and save preferences. Services of this type routinely collect names, email addresses, location information and login credentials, and they sometimes permit sign-in through external social-media accounts. A compromise at a platform holding this volume of user data therefore affects a broad cross-section of individuals who may not consider themselves high-risk targets.

What was likely exposed

The confirmed data types listed in connection with the incident are email addresses, names, geographic locations, IP addresses, usernames, salted password hashes and social-media profile links used for authentication. It is not known whether additional fields such as physical addresses, payment information or private project details were also present. Organisations in this sector commonly store only the data required for account creation and service delivery, yet the exact contents of any single breach remain unconfirmed beyond the fields that have been publicly reported.

What's at stake

For individuals, the primary concerns are the reuse of exposed email addresses in phishing campaigns and the potential for attackers to test recovered password hashes against other services. IP addresses and location data can reveal approximate geographic context, while social-media links may allow further profiling. For the organisation, the breach required notification to tens of millions of users and prompted reviews of authentication and data-storage practices. Such events also contribute to the cumulative record of compromised credentials that security researchers and defenders monitor over time.

What to do if you're exposed

Individuals whose information appears in the dataset should change passwords on Houzz and on any other service where the same password or a close variation was used. Enabling multi-factor authentication reduces the value of stolen password hashes. Monitoring email accounts for unexpected login attempts or unsolicited messages provides an early indicator of misuse. Readers can run a free exposure scan of their email address against known breach data to determine whether their information has surfaced in this or other incidents.

AICompiled with AI assistance from public sources and published under our editorial standards.

Editorial & sourcing policy
Recent Breaches is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data, and we do not hold the data claimed in leak-site listings. Incidents are compiled from publicly accessible sources and threat-intelligence platforms and are reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — write to support@galaxywarden.com or press@recentbreaches.com.
Check if you’re exposed →

How this breach connects

Company

Method

CompanyHouzz security record
73/100
DoxxScan™ · Moderate doxx risk
C- 64Below-average record

1 reported incident on record.

See Houzz’s full breach history →

More recent breaches

IIMJobs Data Breach (2018)December 31, 2018BannerBit Data Breach (2018)December 29, 2018BlankMediaGames Data Breach (2018)December 28, 2018Roll20 Data Breach (2018)December 26, 2018

Latest breaches

Read GalaxyWarden’s full analysis of the Houzz Data Breach (2018) →

Verified breach. Breach data provided in part by Have I Been Pwned, used under CC BY 4.0.

Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.

Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.

ShareXLinkedInFacebookRedditWhatsAppTelegram