Scentbird Data Breach (2020): What Was Exposed & What To Do
SourceBreach data provided in part by Have I Been Pwned, used under CC BY 4.0.
The Scentbird Data Breach (2020) (reported June 22, 2020) exposed Dates of birth, Email addresses, Genders and Names belonging to roughly 5.8M people. If you have an account with them, your information may now be circulating on the open web and with data brokers. Here’s exactly what happened, how to check if you were affected, and what to do next.
Inside the incident
The breach was reported in June 2020 and affected 5.8 million customer records. The data types confirmed as exposed are names, email addresses, genders, dates of birth, passwords stored as bcrypt hashes, and password-strength indicators. No further technical details about the method of access, the precise date of the intrusion, or the duration of exposure have been disclosed in the available reporting. The data set was supplied to Have I Been Pwned by breachbase.pw.
How a breach like this happens
Incidents involving the exposure of customer databases commonly result from unauthorised access to web-application servers or backend storage systems. Attackers may exploit vulnerabilities in login pages, third-party integrations, or misconfigured access controls to extract tables containing user records. Once obtained, the data can be packaged and shared on forums or data-aggregation sites. The use of bcrypt hashing for passwords indicates that stored credentials were protected by a deliberately slow hashing function, though the strength of individual passwords still varies.
Who is Scentbird?
Scentbird operates an online subscription service that delivers fragrance samples to customers on a recurring basis. Like other direct-to-consumer retailers, the company collects standard account and profile information to manage subscriptions, process payments, and personalise recommendations. Such organisations routinely store names, contact details, dates of birth for age verification or marketing segmentation, and login credentials. A breach at a service of this type is consequential because the data set can support targeted account takeovers or identity-related misuse when combined with information from other sources.
What data was at risk
The records made available include names, email addresses, genders, dates of birth, passwords stored as bcrypt hashes, and indicators of password strength. No additional categories of data, such as payment-card details or shipping addresses, are named in the reported summary. The exact contents of any individual record remain unconfirmed beyond these fields.
The real-world impact
Individuals whose information appears in the data set may receive increased volumes of phishing messages sent to the exposed email addresses. If a password was reused elsewhere, the bcrypt hash could be subjected to offline cracking attempts, potentially allowing access to other accounts. Dates of birth and names can assist in identity-verification processes at other services. For the organisation, the incident creates operational costs associated with customer notification, credential resets, and any regulatory reporting obligations that may apply.
If your data was in this breach
Review your email account for any password-reset messages from Scentbird or related services and change the password on the Scentbird account if you still use it. Where the same password or a close variant appears on other sites, update those credentials as well and enable multi-factor authentication where available. You can run a free exposure scan of your email address against known breach data sets to check for additional appearances of your information.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
MEO Data Breach (2020)NetGalley Data Breach (2020)MMG Fusion Data Breach (2020)DriveSure Data Breach (2020)Latest breaches
Read GalaxyWarden’s full analysis of the Scentbird Data Breach (2020) →
Verified breach. Breach data provided in part by Have I Been Pwned, used under CC BY 4.0.
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.