17 million CouchSurfing users’ data for sale on data sharing forum

CloudSEK’s flagship digital risk monitoring platform XVigil discovered a post, on a surface web database marketplace, advertising the information of 16.99 million unique CouchSurfing users.
Updated on
April 19, 2023
Published on
July 20, 2020
Read MINUTES
5
Subscribe to the latest industry news, threats and resources.
CloudSEK has discovered a data leak that contains sensitive information of 16.99 million users of couchsurfing.com. CouchSurfing  is a global homestay and social networking service through which members avail and provide lodging, organize events, and socialize.  

Discovery of the leak

CloudSEK’s flagship digital risk monitoring platform XVigil discovered a post, on a surface web database marketplace, advertising the information of 16.99 million unique CouchSurfing users.  The post was published on 19 July 2020. The seller has shared 22 samples as proof and claims that the data is from July 2020.  

The contents of the leak

The sample records contain 22 users’: 
  • User ID
  • Full name
  • Email
  • Location
  • Last login
  • Subscription status
  • Campaign details

Data verification and validation 

Based on the fields in the database, it appears to be from a marketing campaign. Many of the emails were not publicly available previously and were not found to be part of other documented breaches.

General Recommendations

Even though passwords were not leaked, threat actors can use the email addresses to send spam, phishing emails, and launch other online scams.  So, as a rule of thumb:
  • Use strong passwords.
  • Enable multi-factor authentication for all your online accounts.
  • Don’t open unsolicited email attachments and links, especially from senders you don’t recognize.
  • Don’t share OTPs with third-parties. 
  • Review online accounts and financial statements periodically. 
  • Regularly update your apps and any other software you use.

Get Global Threat Intelligence on Real Time

Protect your business from cyber threats with real-time global threat intelligence data.. 30-day free and No Commitment Trial.
Schedule a Demo
Real time Threat Intelligence Data
More information and context about Underground Chatter
On-Demand Research Services
Dashboard mockup
Global Threat Intelligence Feed

Protect and proceed with Actionable Intelligence

The Global Cyber Threat Intelligence Feed is an innovative platform that gathers information from various sources to help businesses and organizations stay ahead of potential cyber-attacks. This feed provides real-time updates on cyber threats, including malware, phishing scams, and other forms of cybercrime.
Trusted by 400+ Top organisations