Massive Freecycle data breach could affect 7 million users

Data center
(Image credit: Future)

More than seven million people may have had their sensitive information stolen following a data breach that happened on Freecycle’s servers. 

The organization has published a warning on its website, describing what had happened and urging its users to change their login credentials, immediately.

Freecycle is a non-profit organization that connects people looking to exchange used things, instead of throwing them away. 

Freecycle breach

"On August 30th we became aware of a data breach on Freecycle.org,” the organization wrote in its statement. “As a result, we are advising all members to change their passwords as soon as possible.”

"We apologize for the inconvenience and would ask that you watch this space for further pending background."

The attack appears to have happened months previously, before even June, when the Freecycle database was already for sale on the dark web, including data such as usernames, user IDs, email addresses, as well as MD5-hashed passwords. 

Analyzing the screenshots posted by the attackers, BleepingComputer concluded that it was Freecycle founder and executive director Deron Beal who had his credentials stolen, granting the attackers keys to the kingdom. 

Following the discovery of the breach, the organization reached out to the police, it said, and added that users should be wary of possible phishing attacks and other scams coming their way: "While most email providers do a good job at filtering out spam, you may notice that you receive more spam than usual," the warning reads.

"As always, please remain vigilant of phishing emails, avoid clicking on links in emails, and don't download attachments unless you are expecting them." 

Besides phishing, this type of information can also be used in identity theft and wire fraud. 

Freecycle is a major organization with almost 11 million members scattered around more than 5,000 towns around the world.

Sead is a seasoned freelance journalist based in Sarajevo, Bosnia and Herzegovina. He writes about IT (cloud, IoT, 5G, VPN) and cybersecurity (ransomware, data breaches, laws and regulations). In his career, spanning more than a decade, he’s written for numerous media outlets, including Al Jazeera Balkans. He’s also held several modules on content writing for Represent Communications.

Read more
A man looking at a tablet with a brown Best Buy package on the desk in front of him
Huge Christmas data breach - 14 million shipping records leaked, putting shoppers at risk
Representational image of data security
Travel data of almost 500,000 users exposed in Daytrip leak
A graphic showing fleet tracking locations over a city.
Lost & Found tracking site hit by major data breach - over 800,000 could be affected
Someone holding a passport with two boarding passes inside it
Top digital loan firm security slip-up puts data of 36 million users at risk
Cartoon Phishing
One of the largest data leaks ever sees info on 1.5 billion people leaked online
ID theft
Over a million patients potentially hit after another US healthcare provider hit by cyberattack
Latest in Security
Data Breach
Thousands of healthcare records exposed online, including private patient information
China
Juniper patches security flaws which could have let hackers take over your router
Representational image depecting cybersecurity protection
GitLab has patched a host of worrying security issues
Ai tech, businessman show virtual graphic Global Internet connect Chatgpt Chat with AI, Artificial Intelligence.
AI agents can be hijacked to write and send phishing attacks
China
Volt Typhoon threat group had access to American utility networks for the best part of a year
Abstract image of cyber security in action.
MassJacker malware targets those looking for pirated software
Latest in News
Quordle on a smartphone held in a hand
Quordle hints and answers for Monday, March 17 (game #1148)
NYT Strands homescreen on a mobile phone screen, on a light blue background
NYT Strands hints and answers for Monday, March 17 (game #379)
NYT Connections homescreen on a phone, on a purple background
NYT Connections hints and answers for Monday, March 17 (game #645)
Apple iPhone 16 Pro HANDS ON
Leaked iPhone 17 dummy units may have given us our best look yet at all four models
A super close up image of the Google Gemini app in the Play Store
It's official: Google Assistant will be retired for phones this year, with Gemini taking over
Quordle on a smartphone held in a hand
Quordle hints and answers for Sunday, March 16 (game #1147)