Hackers breach crowdfunding site Patreon, dump nearly 15 GB of stolen data online including site's source code, user email addresses, and hashed password data
Gigabytes of user data from hack of Patreon donations site dumped online — The inclusion of source code and databases suggest breach was extensive.
Context & Ripple Effects
The dump is the payoff to a failure that was already documented: security researchers had warned Patreon of a remote-code-execution flaw just five days before hackers got in, and the inclusion of source code and full databases in the ~15 GB release suggests they exploited that development error for deep access rather than a shallow scrape.
The breach also lands mid-wave: weeks later the same publication covered the 000Webhost leak of 13M credentials, and the years after established a secondary market where stolen corpora get re-published — most visibly when a hacker shared data stolen on 18 companies for free on a forum, alongside the Raidforums reposting of rival hacking community Cracked.to's database.
First-order effects
- Every Patreon user's email address and hashed password is now public, exposing them to credential-stuffing against any other service where they reused the password; donors' payment-linked giving activity is likewise in the open.
- Publishing Patreon's source code hands every attacker — not just this one — a roadmap of the site's internal logic, endpoints, and likely remaining weaknesses.
Second-order effects
- Because the hashes will be cracked offline at leisure, the breach keeps paying out long after the news cycle: compromised Patreon credentials feed automated login attempts across email, social, and banking accounts of the same users.
- Forums like Raidforums institutionalize the resale-and-free-release pipeline seen in the Cracked.to and 18-company dumps, so Patreon's data becomes a durable commodity rather than a one-time leak.
Third-order effects
- If platforms treat security headcount as a cost center — a tension that resurfaced when ex-staff said Patreon later laid off its entire cybersecurity team in 2022 while insisting security would not suffer — breach risk becomes structural rather than episodic for creator-economy businesses whose revenue depends on recurring trust.
- The pattern pushes the industry toward assuming breach-and-dump is inevitable: mandatory multi-factor authentication, aggressive hashing upgrades, and breach-notification norms harden around cases like Patreon's rather than preventing them outright.
The trend: Platform breaches are evolving from one-off incidents into permanent exposures, as stolen corpora circulate indefinitely through forum resale channels while the breached companies' security investment rises and falls with cost cycles.