Wattpad — 268 Million Records, and the Passwords Were the Least of It (2020)
If you have an account with Wattpad, here’s what’s now in circulation.
Wattpad hashed its passwords with bcrypt, which held up. The problem is the other eleven fields: bio, date of birth, gender, location, IP address, linked social profiles and personal website, on a platform whose users skew young and write under names they consider private.
What happened
In June 2020 the user-generated stories platform Wattpad suffered a breach exposing 268,765,495 records. The data was sold first and then published on a public hacking forum, where it was broadly shared — the usual progression, and the one that makes a dataset permanent.
The passwords were fine. That is not the story.
Wattpad stored passwords as bcrypt hashes. bcrypt is deliberately slow and individually salted, so mass recovery of the kind that gutted MySpace and LinkedIn is not practical here. If you had a decent password, it is still a decent password.
Most coverage of this breach stops at that reassurance, and it is the wrong place to stop. The catalogue lists eleven data classes for Wattpad, and only one of them is passwords. The others are names, usernames, email addresses, IP addresses, genders, dates of birth, geographic locations, bios, linked social media profiles and personal website URLs.
Read that as an attacker would: this is a pre-assembled dossier that maps a pen name to a real name, an age, a location and every other account the person chose to link. Bcrypt protects none of it, because none of it is hashed. It is just fields.
Who this actually endangers
Wattpad's user base skews young and heavily toward writers publishing under pseudonyms — often work they would not want attached to their legal name, their school or their family. The platform's own profile fields encourage linking out to Instagram, Twitter and personal sites, which is a reasonable thing to ask of a writer building an audience and a catastrophic thing to leak.
A date of birth in this dataset frequently indicates a minor at the time of the breach. Combined with a geographic location and a linked social profile, that is the exact field set used for targeted harassment and for grooming pretexts. This is the breach on the list where the non-credential data does the most harm.
The identity-chain implication
Most breaches give an attacker one edge in the graph — an email address next to a handle. Wattpad gives them a whole subgraph in a single row, because the user filled it in voluntarily: here is my pen name, here is my real name, here is my Instagram, here is my website, here is where I live and when I was born.
When we map identity chains, self-declared profile links are the highest-value and least-recoverable edges, because unlike a password they cannot be rotated — and unlike an inference, they are certain.
What to do now
The work here is de-linking a persona, not changing a credential.
What You Should Do
- Audit what your Wattpad profile linked to — every social profile and personal URL in that bio is now permanently associated with your pen name
- If you wrote under a pseudonym you still care about protecting, assume the pen-name-to-real-name link is public and plan accordingly
- Parents: if a child used Wattpad before mid-2020, their date of birth, location and linked accounts are in this dataset
- Change the password anyway if you reused it elsewhere — bcrypt protects the hash, not a password you also used on a site that stored it badly
- Remove the downstream people-search listings that combine this profile data with address records
What the free scan actually returns
Found on people-search siteswe remove these
These listings are live, public, and legal to remove. That’s what a Deep Sweep buys.
Found in breach recordsverifiedreported — unverified
Each record is labeled: confirmed breach data, or an attacker’s claim no one has verified.
Leaked data cannot be deleted from the internet — anyone claiming otherwise is lying. Broker listings can be removed. We do the second, and show you exactly what to fix from the first.
Report details & sourcing
Related breaches
Crunchbase Massive Personal Records Leak — January 2026
ShinyHunters exfiltrated approximately 2 million records from the business-intelligence platform Cru…
Dubsmash — 162 Million Accounts Sold in a Job Lot (2018)
The video-messaging app used PBKDF2, one of the better choices on this list. Its data still ended up…
Rockstar Games 78 Million Records via Snowflake/Anodot — April 2026
ShinyHunters compromised Rockstar Games via a third-party Snowflake/Anodot analytics instance, exfil…