MacGeneration Data Breach (2022): What Was Exposed & What To Do
SourceBreach data provided in part by Have I Been Pwned, used under CC BY 4.0.
The MacGeneration Data Breach (2022) (reported January 29, 2022) exposed Email addresses, Passwords and Usernames belonging to roughly 101K people. If you have an account with them, your information may now be circulating on the open web and with data brokers. Here’s exactly what happened, how to check if you were affected, and what to do next.
What happened
In January 2022, MacGeneration suffered a data breach affecting 101,000 user accounts. The compromised records included usernames, email addresses, and passwords stored as salted SHA-512 hashes. After identifying the incident, the organisation submitted the data to Have I Been Pwned.
Public information does not specify how the unauthorised access occurred or the precise date range during which the data was taken. No other categories of information are confirmed as exposed in available reports.
How a breach like this happens
Incidents involving the disclosure of usernames, email addresses, and password hashes commonly result from unauthorised access to an organisation’s user database. This access can occur through exploitation of software vulnerabilities, compromised administrative credentials, or misconfigured servers that leave data reachable from the public internet.
Once obtained, the data may be copied and later circulated. Passwords stored only as hashes, even when salted, can still be tested against common values if the hashing implementation is weak or if users have chosen easily guessed passwords. Organisations sometimes learn of such events only after the data appears on public breach repositories.
About MacGeneration
MacGeneration is a French website that publishes news and information about Apple products and services. Like many online publications, it maintains registered user accounts that allow readers to comment on articles or receive newsletters.
Such sites routinely collect email addresses, usernames, and passwords to manage accounts. A breach at a niche technology news outlet can affect readers who may also use similar credentials on other services, increasing the chance that the exposed hashes become useful for attempts to access unrelated accounts.
What was likely exposed
The breach record names three categories of data: usernames, email addresses, and passwords stored as salted SHA-512 hashes. No other data types are listed in the available information.
Organisations of this type typically store account creation dates, IP addresses at registration or login, and possibly newsletter subscription preferences. Whether any of these additional fields were present in the exposed dataset remains unconfirmed.
Why it matters
Email addresses and usernames can be used for targeted phishing or to locate the same individuals on other platforms. Password hashes, even when salted, allow offline attempts to recover the original passwords, particularly if users have reused credentials across sites.
For MacGeneration, the incident required notification steps and the submission of data to a public breach database. For affected individuals, the primary concern is the potential for credential stuffing on other services where the same email and password combination may have been used.
If your data was in this breach
Change the password on your MacGeneration account and on any other site where you used the same or a similar password. Enable two-factor authentication where available, and monitor your email account for unexpected login attempts or password-reset messages.
You can enter your email address into a free exposure scan on Have I Been Pwned to check whether your information appears in this or other known breach datasets.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
GunAuction.com Data Breach (2022)BreachForums Data Breach (2022)Movie Forums Data Breach (2022)Abandonia (2022) Data Breach (2022)Latest breaches
Read GalaxyWarden’s full analysis of the MacGeneration Data Breach (2022) →
Verified breach. Breach data provided in part by Have I Been Pwned, used under CC BY 4.0.
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.