Back to Radar
WO

Wongnai

High

In 2020, a breach at Wongnai exposed 4M users' personal data, including credentials and social profiles.

Records exposed
3,924,454 records
Breach date
Breach Oct 28, 2020
Last update
Updated Nov 5, 2020

What data was exposed?

Fields reported as compromised in this breach record.

Dates of birthEmail addressesGeographic locationsIP addressesNamesPasswordsPhone numbersSocial media profiles

Why does this breach matter?

In-depth analysis of the breach and its implications.

In October 2020, Wongnai, a Thai service platform featuring restaurant, hotel, and attraction information, identified a data breach affecting nearly 4 million user records. Compromised details included sensitive personal data such as birth dates, email addresses, geographic locations, IP addresses, names, passwords stored with MD5 hashing, phone numbers, and social media profile links. This breach was disclosed by Wongnai itself and highlighted the risks associated with insufficiently robust data protection measures.

Impact Analysis

Understanding the scope and consequences of this breach.

User Impact
Users' private data, including passwords, phone numbers, and social profiles, were exposed.
Business Impact
Wongnai faced reputational damage and potential legal scrutiny for the data breach.
Affected Sectors
  • Hospitality
  • Technology
Geographic Impact
  • Thailand

What You Should Do

Recommended actions to take in response to this breach.

If You Were Affected

  • Change all your passwords associated with Wongnai.
  • Monitor accounts for unauthorized activity.
  • Be cautious of targeted phishing attempts.

Preventive Measures

  • Use strong, unique passwords and enable security hashing protocols.
  • Regularly monitor systems for suspicious activities.
  • Educate users on data sharing risks and safety measures.

Frequently Asked Questions

Common questions about this breach and what it means for you.

MD5 is a hashing algorithm considered insecure due to vulnerabilities to attacks such as collision and pre-image exploits.