CSIDB logo
Incident

Social Blade

Incident posture

Attack window
Sep 2022
Location
United States of America
Status
Historical
CIA posture
Available to members
Updated
2025-12-16 00:00

Linked entities

Victim
Social Blade
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Sep 2022
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

Social media analytics platform Social Blade experienced a data breach when a hacker exploited a website vulnerability to access its database, stealing user email addresses, bcrypt-hashed passwords, client IDs, business API tokens, and authentication tokens for connected social accounts. The company confirmed no financial data was compromised and invalidated exposed authorization tokens to prevent misuse, while advising users to reset passwords despite the hashing security. Customers were alerted to potential phishing risks following the incident.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

1 technique

Description

Social media analytics provider Social Blade confirmed a data breach in December 2022 after a threat actor advertised stolen user databases for sale on a hacking forum. The company discovered the incident on December 14th when notified about the hacker's attempt to sell the data, with samples posted publicly that Social Blade verified as authentic. Investigation revealed attackers exploited a vulnerability on the company's website to gain unauthorized access to internal databases. Compromised information included user email addresses, password hashes protected by bcrypt encryption, client identifiers, business API access tokens, authorization tokens for connected social media accounts, and various non-personal operational records. The breach did not expose financial information such as credit card details according to company statements. Social Blade initiated customer notifications on the same day confirming the intrusion and detailing the scope of impacted data.

In response to the breach, Social Blade implemented immediate containment measures including credential cycling for all business API tokens and third-party authorization tokens to invalidate stolen credentials. The company advised users to proactively reset passwords despite employing bcrypt hashing for stored credentials, though no system-wide password reset was mandated. Internal forensic analysis found no evidence of threat actors abusing authentication tokens prior to revocation, noting that third-party tokens typically expired within one hour of creation under normal operations. Impact notifications emphasized heightened phishing risks following the incident and recommended vigilance against fraudulent communications impersonating Social Blade. The organization maintained all payment processing systems remained isolated from compromised infrastructure throughout the event.

Sources

Sources available to members: 1 source.

CSIDB