Flickr
Incident posture
Timeline
Summary
A security incident at the photo-sharing platform Flickr exposed member information through a vulnerability in a third-party email service provider. Upon being alerted to the flaw, the company shut down access to the affected system within hours. The exposed data included names, email addresses, usernames, account types, IP addresses, general location, and Flickr activity data, though passwords and payment card numbers were not affected. The notification noted that unauthorized access may have occurred but did not confirm that any data was actually accessed or stolen by malicious actors, and no threat group publicly claimed responsibility. The impacted email service provider was not publicly named.
Motives
Detailed motive labels are available to members.
TTPs
Detailed technique labels are available to members.
Description
On February 5, 2026, Flickr, a well-known online platform for photo and video hosting, sharing, and management, disclosed a data security incident tied to a vulnerability in a third-party email service provider. According to Flickr's notification, the company was alerted to the flaw on the same day it publicly disclosed the incident. The platform stated that the vulnerability was in a system operated by one of its email service providers, and the flaw may have allowed unauthorized access to some Flickr member information. In response, Flickr shut down access to the affected system within hours of learning about the issue. The company did not publicly name the impacted service provider, and the details of how the vulnerability was discovered have not been disclosed in the available information.
The information potentially exposed through the vulnerability includes Flickr users' names, email addresses, usernames, account types, IP addresses, general location data, and Flickr activity data. Flickr emphasized in its notification that passwords and payment card numbers were not affected by the incident. The company also clarified that its notification indicates only that unauthorized access could have occurred, not that hackers definitively accessed or stole the information. As of the date of the disclosure, no threat actor, including ransomware groups or other cybercrime actors, had publicly claimed to have stolen Flickr data. SecurityWeek reported that no such claim had been observed at the time of their coverage.
Following the discovery of the vulnerability, Flickr took immediate steps to contain the issue by shutting down access to the affected third-party system. The company began notifying users about the incident, advising them to remain vigilant and be cautious of Flickr-themed phishing emails that could potentially exploit the exposed information. The notification did not specify the number of affected users, and the full scope of the incident, including the duration of the vulnerability and the exact nature of the flaw, has not been publicly detailed. Flickr's response focused on user awareness and securing the compromised system, while the investigation into the broader implications of the breach continues.
Sources
Sources available to members: 1 source.