← Hostinger

2019 API server breach — 14M customer records

2019 14.0M records affected Share on X

Data compromised

Usernames, emails, first names, IP addresses, hashed passwords

Technical writeup

Hostinger discovered an unauthorized third party gained access to an internal system API server containing customer data. The breach was discovered on August 23, 2019. Passwords were protected with SHA-1 hashing (later upgraded to SHA-256). Payment information was not affected as financial data was processed through a third-party provider.

Root cause

Unauthorized access to internal API server

References