LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

Recent Breaches › Lumin PDF Data Breach (2019)

CRITICAL severityConfirmedHow we verify

Lumin PDF Data Breach (2019): What Was Exposed & What To Do

RBRecent Breaches Breach Intelligence·April 1, 2019

SourceBreach data provided in part by Have I Been Pwned, used under CC BY 4.0.

Lumin PDF Data Breach (2019)

Reported April 1, 2019. Approximately 15.5M people affected.

CRITICAL
Severity
15.5M
People affected
7
Data types exposed
April 1, 2019
Disclosed
ShareXLinkedInFacebookRedditWhatsAppTelegram

The Lumin PDF Data Breach (2019) (reported April 1, 2019) exposed Auth tokens, Email addresses, Genders and Names belonging to roughly 15.5M people. If you have an account with them, your information may now be circulating on the open web and with data brokers. Here’s exactly what happened, how to check if you were affected, and what to do next.

Severity & verification
CRITICAL severityConfirmed
Account credentials exposed.
Corroborated by an official disclosure or a verified breach feed.
Was your email in the Lumin PDF Data Breach (2019) breach?
15.5M accounts were exposed here. See if yours is one — and every other breach it’s in. 15-sec check, no card.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

In April 2019, the PDF management service Lumin PDF suffered a data breach that exposed records belonging to 15.5 million users. The incident remained undisclosed to the public until September 2019, when the full set of records appeared for download on a hacking forum.

What happened

The breach occurred in April 2019. Records show that user data had been left publicly accessible in a MongoDB instance. The breach was not reported by the company at the time. According to the available information, the organisation was contacted multiple times about the exposure but did not respond to those queries. In September 2019, 15.5 million records were posted on a popular hacking forum, making the incident public.

How a breach like this happens

Incidents involving publicly exposed databases often stem from configuration errors that leave storage systems accessible over the internet without authentication. MongoDB instances have been involved in similar cases when default settings are not changed or when access controls are not applied. Once discovered, such exposures can allow anyone to copy the contents without needing to bypass additional protections. Organisations may remain unaware until the data surfaces elsewhere.

Who is Lumin PDF?

Lumin PDF provides an online service for managing and editing PDF documents. Services of this type typically require users to create accounts, which involves collecting personal identifiers and authentication details. The scale of the exposed records indicates that the service had accumulated a substantial user base by the time of the incident. A breach at a document-management platform can affect individuals who rely on it for both personal and professional files.

What data was at risk

The exposed records included names, email addresses, genders, spoken languages, usernames, bcrypt password hashes, and Google auth tokens. The exact contents of every record have not been independently verified beyond the listing that appeared on the forum. Organisations that operate user accounts commonly store similar categories of information to support login and profile functions, though the precise combination held by Lumin PDF remains limited to what was reported in connection with the 2019 disclosure.

Why it matters

Names and email addresses can be used to target individuals with phishing messages that appear more credible because they reference a service the recipient actually used. Password hashes, even when stored with bcrypt, may be subjected to offline cracking attempts, which can succeed against weaker passwords. Google auth tokens, if still valid, could allow access to linked accounts without the original password. The combination of these data types increases the potential for account misuse across multiple platforms.

Were you affected?

Individuals who created an account with Lumin PDF before September 2019 may have had their information included in the exposed set. A practical first step is to change the password associated with that account and enable any available two-factor authentication. Users can also run a free exposure scan of their email address against known breach data to check for appearances in this or other incidents. Monitoring login activity on linked accounts provides an additional layer of awareness.

AICompiled with AI assistance from public sources and published under our editorial standards.

Editorial & sourcing policy
Recent Breaches is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data, and we do not hold the data claimed in leak-site listings. Incidents are compiled from publicly accessible sources and threat-intelligence platforms and are reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — write to support@galaxywarden.com or press@recentbreaches.com.
Check if you’re exposed →

How this breach connects

Company

Method

CompanyLumin PDF security record
73/100
DoxxScan™ · Moderate doxx risk
C- 64Below-average record

1 reported incident on record.

See Lumin PDF’s full breach history →

More recent breaches

Sonicbids Data Breach (2019)December 30, 2019Go Ninja Data Breach (2019)December 17, 2019GameSprite Data Breach (2019)December 17, 2019Avvo Data Breach (2019)December 17, 2019

Latest breaches

Read GalaxyWarden’s full analysis of the Lumin PDF Data Breach (2019) →

Verified breach. Breach data provided in part by Have I Been Pwned, used under CC BY 4.0.

Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.

Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.

ShareXLinkedInFacebookRedditWhatsAppTelegram