Change.org Data Breach History
WebsiteChange.org is the world’s largest tech platform for people-powered, social change. More than half a billion people across more than 196 countries use our technology-driven petition and campaign tools to speak up on issues they’re passionate about. Approximately 70,000 petitions are created and supported on our platform every month, with 1.7 million new people joining our global network of users every week. People on Change.org have powered tens of thousands of campaign victories worldwide, and m
This page shows all data breaches of Change.org. View the complete breach timeline, records exposed, root causes, and AI breach risk score. BreachHistory tracks disclosed data breaches worldwide.
Data Breach Timeline — All Change.org Breaches
- 2015 2015 Search vulnerability — email addresses exposed 100 records Share
Change.org Data Breach Summary
This page tracks the Change.org data breach history and cybersecurity incidents affecting Change.org (United States). BreachHistory currently indexes 1 publicly disclosed or catalogued incident spanning 2015, with approximately 100 records reported as exposed across all indexed events. These totals may include overlapping datasets or third-party estimates and should not be interpreted as unique affected users.
The Change.org breach timeline includes major data breaches, cyber attacks, data leaks, credential exposures, API abuse, and other security incidents. Each incident provides details on the estimated records exposed, attack method, affected data types, and supporting public sources. Currently, 0 incidents are company-confirmed.
Largest Change.org Data Breaches
The largest indexed incidents include the 2015 Search vulnerability — email addresses exposed. Record counts originating from threat actors or leak sites should be treated as estimates unless confirmed by Change.org or a regulator. Below is the list of large data breaches:
- 2015 2015 Search vulnerability — email addresses exposed — about 100 records exposed · Catalogued incident
What Information Was Exposed?
Depending on the incident, exposed data may include email addresses, physical addresses, and other personal information (PII). The exact data varies between incidents, so review each breach page before assuming your information was affected.
Change.org Data Breach 2026
At the time of this update, no Change.org data breach has been catalogued for 2026. New incidents are added as official disclosures, regulatory filings, or credible cybersecurity reports become available.
What To Do If You Were Affected
If you believe your account may have been involved in a Change.org data breach, change any reused passwords, enable multi-factor authentication (MFA), monitor your account for suspicious activity, and be cautious of phishing emails or fake breach notifications.
This Change.org breach history is maintained by BreachHistory using public disclosures, regulatory filings, security research, and clearly labelled third-party claims. For the complete breach timeline, records exposed, incident details, and AI Breach Risk Score, explore the sections on this page.