Comment hosting service Disqus says hackers stole email addresses and other data for 17.5M users in a 2012 breach; stolen passwords were hashed and salted
Yesterday, on October 5th, we were alerted to a security breach that impacted a database from 2012.
Context & Ripple Effects
Disqus is joining a now-familiar disclosure pattern: breaches from years earlier surfacing only when companies audit legacy databases. Yahoo's confirmation that data from 500M+ accounts was stolen in a 2014 hack set the template for long-lag announcements, and Last.fm's 2012 hack showed how weakly protected those old password stores can be — 96% of its hashed passwords were cracked within two hours.
What distinguishes the Disqus case is the defense: passwords were both hashed and salted, materially raising the cost of cracking compared with Last.fm's outcome. The disclosure lands amid a cluster of comment-and-community-platform breaches, with Quora later reporting a breach affecting about 100M users and Imgur confirming a smaller 2014 incident.
First-order effects
- Email addresses and other profile data for 17.5M Disqus users are now in attackers' hands, and those users face phishing targeted at their Disqus accounts; salted hashes make bulk password cracking far harder than in the Last.fm case.
Second-order effects
- Because Disqus logins are commonly reused credentials, the exposure feeds credential-stuffing attempts against other services holding the same emails — pushing every platform in this disclosure wave (Imgur, Quora) toward mandatory resets and stronger hashing.
Third-order effects
- If years-long gaps between intrusion and discovery remain normal, breach-notification law shifts from punishing late disclosure to mandating the audits and hashing standards that would have caught these legacy databases sooner.
The trend: Community platforms are systematically excavating old breaches — Yahoo, Last.fm, Imgur, Disqus, Quora — turning legacy database hygiene and disclosure timing into a regulatory question rather than a per-company choice.