Skip to main content
  1. Home
  2. Computing
  3. Social Media
  4. News

Timehop data breach may have compromised 21 million email addresses

Add as a preferred source on Google
Image used with permission by copyright holder

Names and email addresses of as many as 21 million Timehop users may have been compromised as a result of a data breach that occurred on July 4. Timehop, a service that aggregates old photos and posts from various social media accounts — including Facebook, Instagram, Twitter, Google Photos, and Dropbox — discovered the attack on its service as it was unfolding, but it took several hours for the company to contain the breach.

“On July 4, 2018, the attacker(s) conducted activities including an attack against the production database, and transfer of data,” the company revealed a few days following the breach. “At 2:43 pm U.S. Eastern Time the attacker conducted a specific action that triggered an alarm, and Timehop engineers began to investigate. By 4:23 p.m., Timehop engineers had begun to implement security measures to restore services and lock down the environment.”

Recommended Videos

Timehop’s initial investigation revealed that no user content was compromised as a result of the breach. Engineers deactivated keys that linked Timehop’s service with other social media platforms as a response, so users will have to re-authenticate with those services. Still, in addition to names and email addresses, as many as 4.7 million phone numbers may have also been exposed as a result of the attack, TechCrunch reported.

“While we were confident that the access keys to those services had not been used, we felt that potential exposure of that content urgently justified a service interruption to ensure that attackers could not, for example, view personal photos,” the company said. “Through conversations with the information security, engineering, and communications staff at these providers, we were able to deactivate the keys and confirm that no photos had been compromised.” Timehop further noted that these tokens would not have given anyone access to private information, such as Facebook Messenger messages or Twitter Direct Messages.

According to the company, the first stage of the attack occurred on December 19, 2017 when an unauthorized user obtained the credentials of an administrative user to create a new administrative-level account. The attacker was able to do this because the original administrative account was not protected by multi-factor authentication, and Timehop has since taken steps to secure accounts to prevent another similar attack from happening. The attacker used the newly created administrative account to log into Timehop’s servers in March and June, with the attack taking place in July.

Although the attacker may have had access to some of your social posts on Facebook, Instagram, and Twitter, Timehop informed users that “there was a short time window during which it was theoretically possible for unauthorized users to access those posts.” Despite the security breach, Timehop maintains that it found “no evidence that any accounts were accessed without authorization,” and it claims that because it pulls only the data that it needs for the service, it was able to minimize a potentially larger exposure.  Timehop has notified law enforcement about the breach and retained the services of a cybersecurity agency to monitor the dark web to ensure that user data doesn’t get leaked.

Chuong Nguyen
Silicon Valley-based technology reporter and Giants baseball fan who splits his time between Northern California and Southern…
Everything Apple announced at its September event: iPhone Duo, iPhone 18 Pro, new Apple Watches, and AirPods 5
Apple packed its biggest September event in years with a foldable iPhone, new watches, and smarter AirPods.
Computer, Electronics, Tablet Computer

The "Surprise and Shine" September launch event was one of Apple's crispest, most elaborate, and most loaded launch events in a while. Instead of leaving the minute details in the spec sheet or fine print, Apple actually included them in its keynote presentation, not just for its big reveal but for all the devices it unveiled on September 9, 2026. 

While the 'Surprise' bit was covered by the new iPhone Duo, 'Shine' probably refers to the new colors in the iPhone 18 Pro lineup. Beyond these, Apple also announced two new Apple Watches and a refresh for the regular AirPods (not the Pro ones). Given that there's a lot of ground to cover, here's everything Apple announced at its September 2026 event. 

Read more
Before You Pay More for DDR5, Think About How Much Memory You Need
The MSI Cubi 5 1MA makes a strong case for looking beyond the newest specs
MSI Cubi 5 1MA compact mini PC with Intel Core processor

There is an easy trap to fall into when buying a new PC. The newer specification usually sounds like the better one, so choosing DDR5 memory over DDR4 can seem like an obvious upgrade. But with memory prices climbing to unusually high levels, it is worth asking whether you will actually benefit from paying more for that extra speed.

For many people buying a PC primarily for work, the answer comes down to how they use it. Everyday tasks such as browsing, email, spreadsheets, presentations, and video calls generally do not need the extremely high memory bandwidth DDR5 offers. Having enough RAM to keep several of those tasks running comfortably can be far more relevant.

Read more
Adobe Acrobat’s latest update could make working with PDFs considerably easier
New Acrobat features make it easier to understand, refine and present information in PDFs
Page, Text, Clapperboard

This post is brought to you in paid partnership with Adobe

PDFs remain one of those unavoidable parts of working life. Reports, research papers, presentations, proposals, financial documents and client material still tend to arrive as PDFs, and the real problem is rarely opening or reading them. It is dealing with everything that comes after: finding the useful information in a lengthy document, understanding it quickly and eventually turning it into something presentable.

Read more