CSIDB logo
Incident

Social Bluebook

Incident posture

Attack window
Oct 2019
Location
United States of America
Status
Historical
CIA posture
Available to members
Updated
2025-11-02 00:00

Linked entities

Victim
Social Bluebook
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Oct 2019
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

A social media platform connecting advertisers with influencers experienced a data breach compromising its entire backend database, exposing approximately 217,000 user accounts. The stolen data included influencer names, email addresses, and passwords protected by SHA-2 hashing, though the method of exfiltration and perpetrators remain unidentified. The company verified the breach after external notification and initiated user alerts while reporting the incident to relevant legal authorities as required by state regulations.

Motives

Detailed motive labels are available to members.

6 motives

TTPs

Detailed technique labels are available to members.

1 technique

Description

In October 2019, Social Bluebook, a Los Angeles-based platform connecting advertisers with social media influencers, suffered a breach resulting in the theft of its entire backend database. The compromised database contained approximately 217,000 user accounts, representing a significant portion of the company's claimed 300,000 influencer network. Exposed information included influencer names, email addresses, and passwords protected with SHA-2 hashing algorithms. The breach remained undetected until March 2020 when TechCrunch obtained and verified the stolen data. Journalists confirmed the authenticity of records by contacting multiple users who validated their personal information. Technical analysis revealed no evidence of password hashes being cracked due to the strong encryption implementation. The attackers' identity, intrusion methods, and data exfiltration techniques were never publicly identified by investigators or the company.

Social Bluebook's co-founder Sam Michie acknowledged the breach upon being presented with a data sample by TechCrunch on March 26, 2020, stating the company had only just become aware of the October 2019 incident. The organization initiated breach notifications to affected users via email and formally reported the incident to the California attorney general's office in compliance with state data protection laws. No evidence emerged suggesting misuse of the exposed credentials prior to public disclosure. The incident highlighted persistent targeting of influencer marketing platforms, exemplified by a separate 2019 case involving exposed Instagram influencer data from an Indian firm. Social Bluebook's response focused on regulatory compliance and user notification without disclosing technical remediation measures or system security enhancements.

Sources

Sources available to members: 1 source.

CSIDB