3D printing site Thingiverse suffers major user data breach

Data Breach
(Image credit: Shutterstock)

About 228,000 users of popular 3D printing platform Thingiverse have reportedly had their authentication details stolen and published on the dark web.

The news of the leak doesn’t come from Thingiverse itself, but rather from Have I Been Pwned (HIBP), which got hold of the leaked details of the compromised accounts after receiving a tip last week.

“Thingiverse had 228k unique email addresses exposed in an Oct 2020 DB backup found circulating last week. Data included usernames, IPs, DoBs and unsalted SHA-1 or bcrypt password hashes,” tweeted HIPB.

TechRadar needs you!

We're looking at how our readers use VPNs with streaming sites like Netflix so we can improve our content and offer better advice. This survey won't take more than 60 seconds of your time, and we'd hugely appreciate if you'd share your experiences with us.

>> Click here to start the survey in a new window <<

HIPB’s creator and maintainer Troy Hunt added that the data has been circulating “extensively” on a popular hacking forum.

Disclosure notice

As if the leak wasn’t bad enough, Hunt says he’s had a frustrating experience getting Thingiverse’s attention.

Hunt claims he tried reaching out to the company via its contact form and also sent a direct message on Twitter, but was forced to tweet the firm in public after failing to hear from the Thingiverse for three days.

By this method, Hunt was able to establish a line of communication with Thingiverse. However, so far he has been unable to secure a disclosure notice from the platform, which he needs in order to bring the leak to the attention of his impacted subscribers.

“228k is also just the unique *real email addresses*; on top of that are well over 2M addresses in the form of webdev+[username] @makerbot.com, alongside password hashes. The highest ID in the users table 2,857,418 so the scope is much bigger,” explained Hunt.

Internal human error

In response to TechRadar Pro’s email seeking comment on the leak, Bennie Sham, PR Manager of Thingiverse’s parent company MakerBot, played down the incident and told us that it was "an internal human error that led to the exposure of some non-sensitive user data for a handful of Thingiverse users.”

While Sham didn’t comment on Hunt’s frustrating dealings with the platform regarding the exposure, she stressed that the affected Thingiverse users have been asked to update their passwords, even though there haven’t been any suspicious attempts to access Thingiverse accounts.

“We apologize for this incident and regret any inconvenience it has caused users. We are committed to protecting our valued stakeholders and assets, through transparency and rigorous security management,” said Sham.

Mayank Sharma

With almost two decades of writing and reporting on Linux, Mayank Sharma would like everyone to think he’s TechRadar Pro’s expert on the topic. Of course, he’s just as interested in other computing topics, particularly cybersecurity, cloud, containers, and coding.

Read more
A man looking at a tablet with a brown Best Buy package on the desk in front of him
Huge Christmas data breach - 14 million shipping records leaked, putting shoppers at risk
Cartoon Phishing
One of the largest data leaks ever sees info on 1.5 billion people leaked online
A digital themed isometric showing a neon padlock in the foreground, and a technological diagram of a processor logic board in the background.
A top online gift card store may have exposed private data on hundreds of thousands of users
Someone holding a passport with two boarding passes inside it
Top digital loan firm security slip-up puts data of 36 million users at risk
Security padlock and circuit board to protect data
Foh&Boh data leak leaves millions of CVs exposed - KFS, Taco Bell, Nordstrom applicants at risk
A computer being guarded by cybersecurity.
Wacom warns users their data may have been stolen in breach
Latest in Security
ID theft
Hackers claim Orange attack, threaten to leak 1TB of data
A computer file surrounded by red laser beams
Free online file converters could infect your PC with malware, FBI warns
Close up of a person touching an email icon.
Criminals are using CSS to get around filters and track email usage
DeepSeek on a mobile phone
More US government departments ban controversial AI model DeepSeek
Ransomware
Fortinet firewall bugs are being targeted by LockBit ransomware hackers
Trojan
Microsoft warns of a devious new RAT malware which can avoid detection with apparent ease
Latest in News
ID theft
Hackers claim Orange attack, threaten to leak 1TB of data
Volvo Gaussian Splatting
Volvo is using AI-generated worlds to make its cars safer and it’s all thanks to something called Gaussian splatting
Image of Asus ROG Ally running Bazzite/SteamOS
This SteamOS update promises a new future for non-Steam Deck handheld PCs – and I can’t wait
Perplexity Squid Game Ad
Perplexity AI drops new Squid Game-inspired ad that pokes fun at Google starring Lee Jung-jae
Pedro Pascal in Apple&#039;s Someday ad promoting the AirPods 4 with Active Noise Cancellation.
Pedro Pascal cures his heartbreak thanks to AirPods 4 (and the power of dance) in this new ad
Frank Grimes confronts Homer Simpson in The Simpsons&#039; Homer&#039;s Enemy episode
Disney+ adds a new continuous Simpsons stream, so you no longer have to spend ages choosing an episode