Skip to main content

Here’s a list of sites and services affected by Cloudbleed, and what to do next

A hand on a laptop in a dark surrounding.
Image used with permission by copyright holder
Last week, we found out about Cloudbleed, a major leak of user data affecting sites and services that use infrastructure provided by Cloudflare. It’s still too early to determine the scale of the problem — but it’s an ideal time to respond if you’re looking to avoid the fallout.

Cloudbleed refers to a memory leak that caused user data from apps and websites that use Cloudflare’s services to be splashed across the internet, and is being compared to the Heartbleed bug that reared its head in 2014. Unfortunately, it’s thought that some of the data leaked as a result of Cloudbleed may have been cached by search engines, meaning that malicious entities could have intercepted it, according to a report from Gizmodo.

Cloudflare has such an enormous list of clients that it’s difficult to list every single site and service that could be affected — although an effort to do just that is in progress on GitHub. Here’s a list of some of more commonly used domains that could have had user data leaked (although there’s no confirmation that they’ve been compromised as of yet):

  • uber.com
  • yelp.com
  • medium.com
  • 4chan.com
  • bitcoin.de
  • fitbit.com
  • authy.com
  • tfl.gov.uk
  • okcupid.com
  • discordapp.com
  • feedly.com
  • thepiratebay.org
  • pastebin.com
  • change.org
  • puu.sh

The above is by no means a definitive list, as millions of domains could potentially be at risk. However, it should demonstrate the variety of services that could be affected.

To check whether any sites or apps you use are at risk, you can scour the full list on GitHub, or use the Does it use Cloudflare? web tool. However, most internet users are likely to hold an account on at least one affected site, so password refreshes are recommended for all.

Changing out every password you are currently using may seem extreme, but the stakes are high. If your user data has been leaked, and you use the same password for multiple sites, it might be possible for a stranger to gain access to all kinds of services on your behalf.

As such, it’s well worth doing a sweep now, and changing up your passwords to ensure that you’re kept safe. The inconvenience of spending a hour or two completing the task is a small price to pay for peace of mind.

This might also be a good time to improve your online security across the board. If you’re not already using a password manager and two-factor authentication to keep your accounts safe, there’s no better time to implement these services.

Above all else, vigilance is key. This is an evolving situation, since the problem was only made public a matter of days ago, and there are so many domains that could be affected. Keep a close eye on important accounts, and if you notice anything suspicious, make sure to follow up.

Editors' Recommendations

Brad Jones
Former Digital Trends Contributor
Brad is an English-born writer currently splitting his time between Edinburgh and Pennsylvania. You can find him on Twitter…
I need to change how I use Apple tech in 2024. Here’s how I’m going to do it
Blue Titanium iPhone 15 Pro showing Disney Emoji Blitz.

I’ve had Apple products for almost as long as I’ve been interested in tech, yet in all that time, I’ve never really put much thought into how I use my devices. But, like many people squinting bleary-eyed and hungover into the dawning of a new year, I’ve realized it’s about time I made some changes.

I’m a real book lover – letting me wander into a bookstore unaccompanied is intensely dangerous for my wallet – yet I’m barely making any progress on my reading backlog because I spend so much time on my iPhone. If I’m ever going to get through the reams of books lining my bookshelves, I’ve got to do things a little differently. And that’s what my 2024 New Year’s tech resolution is all about.
Not a blanket ban

Read more
What AMD needs to do to beat Nvidia in 2024
The AMD Radeon RX 7900 XTX graphics card.

In this generation of GPUs, it's not AMD that has the best graphics cards -- it's still Nvidia. AMD's offerings have been strong, but Nvidia trumps it in pure performance, reaching for the stars with the wildly overpriced RTX 4090 while AMD keeps things slightly more reasonable with the RX 7900 XTX.

What can AMD do to turn things around and come out on top in 2024? Will it gain an edge over Nvidia? Signs are pointing to an interesting battle ahead, but for AMD to win, there are a few things that need to happen.
Is AMD as good as it can be in 2023?

Read more
A major Windows update just launched. Here’s what’s new
Person using Windows 11 laptop on their lap by the window.

Microsoft has just announced the latest update to Windows 11, which brings the operating system up to version 23H2. This is a cumulative update that comes with some of the most exciting features already announced in September, including Copilot, and brings some changes to Teams, among other things. Here's what's new and how to get it on your own PC.

When Microsoft first announced Copilot during its September event, many thought that it'd be available right away -- and it was, but not widely. Now, with the 23H2 update, Copilot should be downloaded and toggled on by default, alongside everything else that was announced during the Surface event. Some new things are on the way, too.

Read more