Back to Blog
critical severity June 29, 2020 · 3 min read

Wattpad — 268 Million Records, and the Passwords Were the Least of It (2020)

If you have an account with Wattpad, here’s what’s now in circulation.

Wattpad hashed its passwords with bcrypt, which held up. The problem is the other eleven fields: bio, date of birth, gender, location, IP address, linked social profiles and personal website, on a platform whose users skew young and write under names they consider private.

A pen name connected outward to real-world identifiers

What happened

In June 2020 the user-generated stories platform Wattpad suffered a breach exposing 268,765,495 records. The data was sold first and then published on a public hacking forum, where it was broadly shared — the usual progression, and the one that makes a dataset permanent.

Caught in this breach?
You can’t unleak a breach. You can take away what it’s worth.
Deep Sweep shows you every leak tied to you and exactly what to change. Then it strips your name, address and family off the look-up sites that turn a leaked record into somebody knocking on your door — $29 one-time, includes 30 days of Protection. We write to 582 companies. No subscription to start.
Scan free, then Deep Sweep — $29 →
Not ready yet? Run a free breach check on this email
We’ll check it against 13.1B+ leaked records right now — no account needed. Continuous monitoring & alerts are part of Protection.

The passwords were fine. That is not the story.

Wattpad stored passwords as bcrypt hashes. bcrypt is deliberately slow and individually salted, so mass recovery of the kind that gutted MySpace and LinkedIn is not practical here. If you had a decent password, it is still a decent password.

Most coverage of this breach stops at that reassurance, and it is the wrong place to stop. The catalogue lists eleven data classes for Wattpad, and only one of them is passwords. The others are names, usernames, email addresses, IP addresses, genders, dates of birth, geographic locations, bios, linked social media profiles and personal website URLs.

Read that as an attacker would: this is a pre-assembled dossier that maps a pen name to a real name, an age, a location and every other account the person chose to link. Bcrypt protects none of it, because none of it is hashed. It is just fields.

Who this actually endangers

Wattpad's user base skews young and heavily toward writers publishing under pseudonyms — often work they would not want attached to their legal name, their school or their family. The platform's own profile fields encourage linking out to Instagram, Twitter and personal sites, which is a reasonable thing to ask of a writer building an audience and a catastrophic thing to leak.

A date of birth in this dataset frequently indicates a minor at the time of the breach. Combined with a geographic location and a linked social profile, that is the exact field set used for targeted harassment and for grooming pretexts. This is the breach on the list where the non-credential data does the most harm.

The identity-chain implication

Most breaches give an attacker one edge in the graph — an email address next to a handle. Wattpad gives them a whole subgraph in a single row, because the user filled it in voluntarily: here is my pen name, here is my real name, here is my Instagram, here is my website, here is where I live and when I was born.

When we map identity chains, self-declared profile links are the highest-value and least-recoverable edges, because unlike a password they cannot be rotated — and unlike an inference, they are certain.

What to do now

The work here is de-linking a persona, not changing a credential.

What You Should Do

  1. Audit what your Wattpad profile linked to — every social profile and personal URL in that bio is now permanently associated with your pen name
  2. If you wrote under a pseudonym you still care about protecting, assume the pen-name-to-real-name link is public and plan accordingly
  3. Parents: if a child used Wattpad before mid-2020, their date of birth, location and linked accounts are in this dataset
  4. Change the password anyway if you reused it elsewhere — bcrypt protects the hash, not a password you also used on a site that stored it badly
  5. Remove the downstream people-search listings that combine this profile data with address records

What the free scan actually returns

Sample resultyou@email.comIllustrative — not a real person

Found on people-search siteswe remove these

These listings are live, public, and legal to remove. That’s what a Deep Sweep buys.

value redacted in this sampleage, relatives, address historySpokeo
value redacted in this samplephone, household, property recordsBeenVerified
value redacted in this sample582 companies checked

Found in breach recordsverifiedreported — unverified

Each record is labeled: confirmed breach data, or an attacker’s claim no one has verified.

verifiedvalue redacted in this samplepassword + phone · 2024telecom breach
unverifiedvalue redacted in this sampleclaimed in ransomware listing · 2026leak-site claim

Leaked data cannot be deleted from the internet — anyone claiming otherwise is lying. Broker listings can be removed. We do the second, and show you exactly what to fix from the first.

Were you a Wattpad customer?
Wattpad is one breach. Your email is probably in others.
268.8M records accounts were exposed here. Check whether yours is one — and find every other leak tied to the same address, in about 15 seconds. No account, no card.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

Report details & sourcing

Severity Critical
Disclosed June 29, 2020
Last reviewed July 22, 2026
Affected 268.8M records
Data exposed Email addressesUsernamesNamesPasswordsDates of birthGendersGeographic locationsIP addresses +3 more
Editorial & sourcing policy
GalaxyWarden is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data. Breach information is compiled from publicly accessible sources and threat-intelligence platforms, and is reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — see our content & takedown policy or write to support@galaxywarden.com.
Share this Post on X Reddit Email