Menu
Browse

Cyber Incident Victim: Weebly

Date:

Feb 2016

Location:

United States of America

Summary

A website-building platform suffered a breach compromising over 43 million accounts, with stolen data including usernames, email addresses, IP addresses, and passwords protected by bcrypt hashing. The company confirmed unauthorized access but found no evidence of customer website intrusions or fraudulent use of payment information, noting full credit card details weren't stored on their servers. Affected users were notified with mandatory password resets implemented. Separately, a location-based service reportedly had over 22 million accounts exposed containing personal identifiers, though it denied any breach occurred following internal investigation.

CIA Posture Motives Tactics, Techniques & Procedures
Available to members 1 motive 2 techniques
Threat Actors Type Location
0 actors Available to members Available to members

Description

In February 2016, attackers compromised Weebly, a website-building platform, resulting in the theft of over 43.4 million user accounts. The breach remained undisclosed until October 20, 2016, when LeakedSource, a breach notification site, published details of the incident alongside an unrelated Foursquare data exposure. Analysis of a data sample confirmed stolen records contained usernames, email addresses, IP addresses, and passwords protected by bcrypt hashing. Weebly subsequently acknowledged the breach but emphasized investigators found no evidence of unauthorized access to customer websites or fraudulent use of payment card data, noting the company did not store complete credit card numbers on its servers. The scale of the breach ranked among the largest reported that year, though the exact method of intrusion and attacker identity remained unconfirmed in public disclosures.

Cyber Incident Image

Weebly initiated customer notifications following LeakedSource’s disclosure, mandating password resets as a precautionary measure. The company’s public statement stressed ongoing internal reviews but did not specify whether forensic investigations identified vulnerability root causes or intrusion timelines beyond the February 2016 attack window. While the bcrypt protection reduced immediate credential misuse risks, the exposure of email addresses and IP addresses created potential phishing and targeting vulnerabilities for affected users. No follow-up reports confirmed malicious exploitation of the stolen Weebly data, and the company maintained its service operations without disclosing disruptions. The incident highlighted third-party breach notification services’ role in forcing disclosures, as Weebly’s confirmation occurred only after external analysis of the leaked dataset.

Sources
Sources available to members
1 source