/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

Comment hosting service Disqus says hackers stole email addresses and other data for 17.5M users in a 2012 breach; stolen passwords were hashed and salted

Yesterday, on October 5th, we were alerted to a security breach that impacted a database from 2012.

The Disqus Blog Jason Yan

Context & Ripple Effects

Disqus is joining a now-familiar disclosure pattern: breaches from years earlier surfacing only when companies audit legacy databases. Yahoo's confirmation that data from 500M+ accounts was stolen in a 2014 hack set the template for long-lag announcements, and Last.fm's 2012 hack showed how weakly protected those old password stores can be — 96% of its hashed passwords were cracked within two hours.

What distinguishes the Disqus case is the defense: passwords were both hashed and salted, materially raising the cost of cracking compared with Last.fm's outcome. The disclosure lands amid a cluster of comment-and-community-platform breaches, with Quora later reporting a breach affecting about 100M users and Imgur confirming a smaller 2014 incident.

First-order effects

  • Email addresses and other profile data for 17.5M Disqus users are now in attackers' hands, and those users face phishing targeted at their Disqus accounts; salted hashes make bulk password cracking far harder than in the Last.fm case.

Second-order effects

  • Because Disqus logins are commonly reused credentials, the exposure feeds credential-stuffing attempts against other services holding the same emails — pushing every platform in this disclosure wave (Imgur, Quora) toward mandatory resets and stronger hashing.

Third-order effects

  • If years-long gaps between intrusion and discovery remain normal, breach-notification law shifts from punishing late disclosure to mandating the audits and hashing standards that would have caught these legacy databases sooner.

The trend: Community platforms are systematically excavating old breaches — Yahoo, Last.fm, Imgur, Disqus, Quora — turning legacy database hygiene and disclosure timing into a regulatory question rather than a per-company choice.