Skip to main content

WHMCS data breach

The WHMCS breach happened on May 21, 2012 and exposed 134,047 accounts. 10 kinds of data were exposed.

Overview

Site
whmcs.com
Breach date
May 21, 2012
Recorded on
June 28, 2016
Accounts exposed
134,047
Exposed data
Email addresses, Email messages, Employers, IP addresses, Names, Partial credit card data, Passwords, Payment histories, Physical addresses, Website activity
Risk score
89 out of 100

Risk based on the exposed data

This breach scores 89 out of 100. The score is driven mostly by Passwords, Email messages, Partial credit card data.

The risk score is a guide to how dangerous a breach is, judged by the kinds of data exposed. The number of accounts is not included.

Breaches from the same period

What affected users should do

  • Change your WHMCS password, and also change it on any other service where you used the same password. You can create a new one with the password generator.
  • Turn on two-factor authentication for your login.
  • Card or bank details were exposed, so check your statements and contact your card issuer or bank about any charges you do not recognize.

Create a new password →

This site organizes publicly available information about data breaches. Data as of July 28, 2018. Breach dates are as originally listed; when only the month is known, the date is recorded as the 1st.