2012 — eHarmony: ~1, 1.5M records
Data compromised
Passwords (SHA-1 unsalted)
Technical writeup
Jun 2012. ~1.5M hashed passwords (SHA-1, unsalted) stolen and posted online. Same hacker 'dwdm' as LinkedIn breach; 8M+ passwords across sites. eHarmony described as 'small fraction' of 20M users. Unsalted hashes easily cracked. Company reset affected passwords.
Root cause
Unauthorized access; unsalted SHA-1 password hashing.