Back to Blog
high severity October 03, 2020 · 3 min read

Gravatar — 114 Million Email Addresses Recovered From Avatar URLs (2020)

If you have an account with Gravatar, here’s what’s now in circulation.

Gravatar identifies you by the MD5 hash of your email address, published in the URL of your avatar on every site that uses it. Scraping the API yielded 167 million profiles; 114 million of those hashes were cracked back to the original addresses. Gravatar disputes that this was a breach.

One avatar hash recurring across unrelated websites

What happened

In October 2020 a security researcher published a technique for scraping large volumes of data from Gravatar, the service that supplies a single globally recognised avatar across many websites. 167 million names, usernames and MD5 hashes of email addresses were subsequently scraped and distributed. 114 million of those MD5 hashes were cracked and redistributed alongside the source hash, revealing the original email address.

Caught in this breach?
You can’t unleak a breach. You can take away what it’s worth.
Deep Sweep shows you every leak tied to you and exactly what to change. Then it strips your name, address and family off the look-up sites that turn a leaked record into somebody knocking on your door — $29 one-time, includes 30 days of Protection. We write to 582 companies. No subscription to start.
Scan free, then Deep Sweep — $29 →
Not ready yet? Run a free breach check on this email
We’ll check it against 13.1B+ leaked records right now — no account needed. Continuous monitoring & alerts are part of Protection.

Gravatar's position, published after the addresses became searchable in HIBP, is that it was not hacked — the data was gathered from a public API doing what it was designed to do. That is accurate, and it is the interesting part.

The design decision at the centre of this

Gravatar works by identifying you with the MD5 hash of your email address. When a site shows your avatar, it builds an image URL containing that hash. The hash is therefore published, by design, on every page where your avatar appears — every WordPress comment, every developer forum, every profile.

MD5 is fast and unsalted, and email addresses are low-entropy: they follow predictable patterns and can be generated in bulk. Hashing a candidate list and matching against a published hash is trivially cheap. Around two thirds of the scraped hashes fell.

So there were no passwords here, and nothing to rotate. What leaked is the identifier — and unlike a password, an email address is the thing everything else is keyed on.

Why this is the identity-chain breach

Every other entry on this list gives an attacker data about a person at one site. Gravatar gives them a join key that works across every site the person commented on.

Consider what falls out. A pseudonymous commenter on a technical blog has an avatar. That avatar's URL contains the MD5 of their email. If that hash appears in the cracked set, their email address is now known — and the same hash on a different site, under a different pseudonym, proves the two accounts are the same person.

That is deanonymisation across unrelated platforms, from data the sites published voluntarily and considered harmless. For anyone who maintained separate identities across communities — which is most people with a professional life and a hobby — this is the breach that collapses them together.

What was and was not exposed

To be precise, because this incident attracts exaggeration: the exposed classes are email addresses, names and usernames. No passwords, no addresses, no payment data. The severity comes entirely from the linkage the identifier enables, not from the richness of any single record.

What to do now

What You Should Do

  1. Check which email address your Gravatar uses — that address is derivable from every site where your avatar appears
  2. Use a dedicated address for public commenting, so the join key links only your public identity
  3. Audit whether the same avatar appears under pseudonyms you intended to keep separate; identical avatars imply an identical email address
  4. Do not bother changing a password for this one — none were exposed, and the exposure is an identifier, not a credential
  5. Treat this as the reason to compartmentalise addresses generally: the linkage, not the leak, is the harm

What the free scan actually returns

Sample resultyou@email.comIllustrative — not a real person

Found on people-search siteswe remove these

These listings are live, public, and legal to remove. That’s what a Deep Sweep buys.

value redacted in this sampleage, relatives, address historySpokeo
value redacted in this samplephone, household, property recordsBeenVerified
value redacted in this sample582 companies checked

Found in breach recordsverifiedreported — unverified

Each record is labeled: confirmed breach data, or an attacker’s claim no one has verified.

verifiedvalue redacted in this samplepassword + phone · 2024telecom breach
unverifiedvalue redacted in this sampleclaimed in ransomware listing · 2026leak-site claim

Leaked data cannot be deleted from the internet — anyone claiming otherwise is lying. Broker listings can be removed. We do the second, and show you exactly what to fix from the first.

Were you a Gravatar customer?
Gravatar is one breach. Your email is probably in others.
114.0M email addresses accounts were exposed here. Check whether yours is one — and find every other leak tied to the same address, in about 15 seconds. No account, no card.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

Report details & sourcing

Severity High
Disclosed October 03, 2020
Last reviewed July 22, 2026
Affected 114.0M email addresses
Data exposed Email addressesNamesUsernames
Editorial & sourcing policy
GalaxyWarden is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data. Breach information is compiled from publicly accessible sources and threat-intelligence platforms, and is reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — see our content & takedown policy or write to support@galaxywarden.com.
Share this Post on X Reddit Email