Uiggy Data Breach (2016): What Was Exposed & What To Do
SourceBreach data provided in part by Have I Been Pwned, used under CC BY 4.0.
The Uiggy Data Breach (2016) (reported June 1, 2016) exposed Email addresses, Genders, Names and Social connections belonging to roughly 2.7M people. If you have an account with them, your information may now be circulating on the open web and with data brokers. Here’s exactly what happened, how to check if you were affected, and what to do next.
What happened
The breach affected the Uiggy Facebook application. Public records state that 4.3 million accounts were exposed in total, with email addresses present for 2.7 million of them. Additional fields disclosed in the incident included names, genders, and Facebook IDs. Details on the method of access, the exact timing of the intrusion, or the volume of records ultimately accessed by third parties remain undisclosed in available reports.
How a breach like this happens
Incidents involving third-party applications on social platforms often stem from vulnerabilities in the application's own infrastructure rather than the underlying platform. Attackers may obtain unauthorized access to stored user records through compromised credentials, unpatched software, or misconfigured databases. Once inside, they can copy large volumes of data that the application has collected with user consent. Such events are frequently identified only after the data appears in public or underground forums.
Who is Uiggy?
Uiggy operated as a Facebook application, a category of third-party software that integrates with the Facebook platform to provide additional features to users. Applications of this type routinely request permission to access profile information, friend lists, and activity data in order to function. A compromise at this layer can therefore surface details that users have shared within the app environment, separate from the core Facebook service.
What data was at risk
The records named in connection with the incident include email addresses, genders, names, social connections, and website activity. The reported summary also references Facebook IDs of the account owners. Exact contents of the exposed dataset have not been independently verified beyond these categories, and organizations of this type commonly store additional profile-related information whose presence in the breach remains unconfirmed.
Why it matters
Exposure of email addresses combined with names and social connections can facilitate targeted phishing or unwanted contact. Facebook IDs and activity data may allow third parties to map relationships or reconstruct usage patterns even without passwords. For the organization, the event highlights the storage and protection obligations that accompany collection of user data through platform integrations.
If your data was in this breach
Individuals can begin by reviewing recent account activity on any associated email addresses and enabling two-factor authentication where available. Monitoring for unusual login attempts or unsolicited messages provides an early indicator of misuse. A free exposure scan of an email address against known breach data can help confirm whether the address appears in public records of this or other incidents.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
Data Enrichment Records Data Breach (2016)RankWatch Data Breach (2016)Modern Business Solutions Data Breach (2016)Justdate.com Data Breach (2016)Latest breaches
Read GalaxyWarden’s full analysis of the Uiggy Data Breach (2016) →
Verified breach. Breach data provided in part by Have I Been Pwned, used under CC BY 4.0.
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.