LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

Recent Breaches › MDPI Data Breach (2016)

MEDIUM severityConfirmedHow we verify

MDPI Data Breach (2016): What Was Exposed & What To Do

RBRecent Breaches Breach Intelligence·August 30, 2016

SourceBreach data provided in part by Have I Been Pwned, used under CC BY 4.0.

MDPI Data Breach (2016)

Reported August 30, 2016. Approximately 845K people affected.

MEDIUM
Severity
845K
People affected
4
Data types exposed
August 30, 2016
Disclosed
ShareXLinkedInFacebookRedditWhatsAppTelegram

The MDPI Data Breach (2016) (reported August 30, 2016) exposed Email addresses, Email messages, IP addresses and Names belonging to roughly 845K people. If you have an account with them, your information may now be circulating on the open web and with data brokers. Here’s exactly what happened, how to check if you were affected, and what to do next.

Severity & verification
MEDIUM severityConfirmed
Contact / identity PII exposed.
Corroborated by an official disclosure or a verified breach feed.
Was your email in the MDPI Data Breach (2016) breach?
845K accounts were exposed here. See if yours is one — and every other breach it’s in. 15-sec check, no card.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

In August 2016, the Swiss open-access publisher MDPI experienced a data incident in which 17.5 GB of material was obtained from an unprotected MongoDB instance. The material included email exchanges between the publisher and its authors and reviewers, encompassing 845,000 unique email addresses along with associated names, IP addresses, and message content. The incident was reported on 30 August 2016.

The event is notable because it involved a large volume of correspondence within the academic publishing process and because the data source was left accessible without authentication. MDPI stated that the database has since been secured and that the exposed material did not include data of a sensitive nature.

Inside the incident

The data originated from a MongoDB instance that was not protected by authentication controls at the time of the exposure. The contents consisted of email exchanges between MDPI staff and external authors and reviewers. The publisher confirmed that the instance has been protected since the incident and that no notification to subscribers was issued, citing the public availability of author and reviewer contact details on its website.

No further technical details on the duration of exposure or the method of discovery have been disclosed in public reporting. The total number of affected individuals is given as 845,000 unique email addresses.

How a breach like this happens

Incidents involving unprotected databases commonly occur when administrative interfaces or data stores are configured for internal use but remain reachable from the public internet without password or network restrictions. MongoDB instances have historically been involved in such exposures when default settings that disable authentication are left unchanged in production environments.

Once discovered through automated scanning, an unprotected database can be read in full without any interaction with the owning organisation’s other systems. Remediation typically involves enabling authentication, restricting network access, and applying encryption or logging controls.

MDPI and its sector

MDPI is a Swiss-based publisher of peer-reviewed open-access journals. Organisations of this type maintain records of individuals who submit manuscripts or serve as reviewers, including contact details and correspondence necessary to manage the editorial process.

Because scholarly publishing relies on direct communication with researchers worldwide, the sector routinely holds large volumes of email addresses and message content. A compromise of such records can therefore affect a broad academic population even when the material itself is not classified as highly sensitive.

The information in question

The exposed data types explicitly named are email addresses, email messages, IP addresses, and names. MDPI stated that the material did not include data of a sensitive nature.

Exact details of every field contained in the 17.5 GB dataset have not been published. Organisations in academic publishing typically store additional metadata such as submission identifiers or review comments, but it is unconfirmed whether such fields were present in this instance.

What's at stake

Individuals whose email addresses and associated messages were exposed face an increased likelihood of receiving unsolicited messages or targeted phishing attempts that reference their prior contact with the publisher. Because the addresses belong to researchers and reviewers, the information could also be used to craft messages that appear contextually relevant.

For the organisation, the incident highlights the consequences of leaving production data stores accessible without authentication. While MDPI assessed the material as non-sensitive, the volume of correspondence still required subsequent security measures to prevent further access.

What to do if you're exposed

Anyone who suspects their email address may have been included can begin by monitoring the account for unusual login attempts or unsolicited messages that reference MDPI or academic submissions. Enabling two-factor authentication on the email account and any linked services reduces the chance that exposed addresses can be used for account takeover.

Readers may also run a free exposure scan of their email address against known breach data to determine whether their information appears in public records of this or other incidents. Keeping software and database configurations updated and restricting remote access remain standard preventive steps for any organisation handling similar records.

AICompiled with AI assistance from public sources and published under our editorial standards.

Editorial & sourcing policy
Recent Breaches is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data, and we do not hold the data claimed in leak-site listings. Incidents are compiled from publicly accessible sources and threat-intelligence platforms and are reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — write to support@galaxywarden.com or press@recentbreaches.com.
Check if you’re exposed →

How this breach connects

Company

Method

CompanyMDPI security record
74/100
DoxxScan™ · Moderate doxx risk
B+ 85Strong record

1 reported incident on record.

See MDPI’s full breach history →

More recent breaches

Data Enrichment Records Data Breach (2016)December 23, 2016RankWatch Data Breach (2016)November 19, 2016Modern Business Solutions Data Breach (2016)October 8, 2016Justdate.com Data Breach (2016)September 29, 2016

Latest breaches

Read GalaxyWarden’s full analysis of the MDPI Data Breach (2016) →

Verified breach. Breach data provided in part by Have I Been Pwned, used under CC BY 4.0.

Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.

Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.

ShareXLinkedInFacebookRedditWhatsAppTelegram