Imgur confirms hackers stole 1.7M email addresses and passwords hashed with SHA-256 algorithm in 2014 hack
The hackers stole email addresses and passwords. — Imgur, one of the world's most visited websites, has confirmed a hack dating back to 2014. — The company confirmed to ZDNet …
Context & Ripple Effects
Imgur's confirmation lands one month after Disqus disclosed its own long-dormant breach — hackers had taken data on 17.5M users back in 2012, revealed only in October 2017. The pattern echoes Yahoo, which waited two years to confirm that data from 500M+ accounts was stolen in 2014.
What makes the Imgur case notable is the hashing choice: SHA-256 is a fast general-purpose hash, not a password-specific one. The Last.fm precedent shows why that matters — in the 2012 Last.fm hack, 96% of hashed passwords were cracked within two hours.
First-order effects
- Users with accounts tied to those 1.7M email addresses face immediate password-reset pressure, since fast-hashed credentials from 2014 are realistically crackable offline.
- Imgur joins Disqus and Yahoo in the awkward position of disclosing multi-year-old breaches, absorbing reputational cost for an intrusion that predates its current security posture.
Second-order effects
- Cracked Imgur credentials feed credential-stuffing attempts against other services where users reused passwords, spreading the blast radius well beyond Imgur itself.
- Every late disclosure raises the bar for peer consumer platforms to re-audit historical logs and proactively confirm or deny old intrusions before leaked data surfaces elsewhere.
Third-order effects
- If old breaches keep surfacing years after the fact — Last.fm 2012, Disqus 2012, Yahoo 2014, now Imgur 2014 — breach disclosure becomes a rolling archive problem rather than a single-event announcement, pushing regulators toward stricter notification timelines.
- Fast generic hashes like SHA-256 are structurally discredited for password storage, accelerating migration toward deliberately slow, salted password-hashing schemes across the industry.
The trend: Old breaches are being confirmed years late as stolen databases circulate and get sold, turning legacy hashing choices into today's public liabilities.