CSIDB logo
Incident

Letterboxd

Incident posture

Attack window
Feb 2024
Location
United States of America
Status
Historical
CIA posture
Available to members
Updated
2026-01-03 18:49

Linked entities

Victim
Letterboxd
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Feb 2024
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

A film-focused social media platform experienced a data breach after attackers compromised an employee account, leading to unauthorized access and theft of user information. The incident impacted under 1% of accounts, exposing email addresses, private and watchlists, and deleted content, though no passwords, payment details, or account takeover capabilities were accessed. The organization isolated the compromised account post-discovery and implemented security enhancements to mitigate future risks. While unable to identify affected users specifically, the platform cautioned that stolen data could facilitate phishing attempts targeting members.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

1 technique

Description

On February 15, 2024, Letterboxd detected unauthorized access to its systems following the compromise of an employee account by third-party attackers. The breach resulted in the theft of user data belonging to fewer than 1% of the platform’s user base. Letterboxd immediately isolated and secured the compromised account upon discovery to prevent further unauthorized activity. The attackers obtained access to email addresses, private Lists, Watchlists, and deleted content associated with affected accounts. No passwords, payment information, or other credentials enabling account takeover were accessed or exfiltrated during the incident. Letterboxd implemented unspecified security measures to reduce the likelihood of similar incidents occurring in the future. The company did not identify which specific users were impacted by the breach but notified all users via email about the incident.

The stolen data poses a risk of targeted phishing campaigns leveraging exposed email addresses and user activity details like Lists and Watchlists. Letterboxd acknowledged this secondary threat but confirmed no direct compromise of account integrity or financial systems. The platform advised users to employ unique passwords and enable two-factor authentication as general security precautions, though these measures were not presented as incident-specific remedies. No evidence suggests operational disruption to Letterboxd’s services beyond the data theft, and the breach investigation concluded without identifying additional compromised systems or threat actor attribution. The company’s public disclosure emphasized transparency regarding the scope of accessed data while confirming the containment of the breach to the initially identified entry vector.

Sources

Sources available to members: 1 source.

CSIDB