# Gravatar

WHAT HAPPENED

In October 2020, a security researcher published a technique for scraping large
volumes of data from Gravatar
[https://www.bleepingcomputer.com/news/security/online-avatar-service-gravatar-allows-mass-collection-of-user-info/],
the service for providing globally unique avatars. 

167 million names, usernames and email addresses used to reference users'
avatars were later scrapped and distributed within the hacking community.


HOW TO STAY SAFE

1. Change the password on your email account
Since this leak exposed email addresses, updating your email password will
reduce the risk of someone trying to access your inbox. This is especially
important if you use the same password on other websites. 

Follow one of our step-by-step guides depending on which email provider you use:

How to Change Your Gmail Password
[https://help.futureproof.app/article/1032-how-to-change-your-gmail-password]

How to Change Your Yahoo Password
[https://help.futureproof.app/article/1033-how-to-change-your-yahoo-password]

How to Change Your AOL Password
[https://help.futureproof.app/article/1034-how-to-change-your-aol-password]

How to Change Your iCloud Password
[https://help.futureproof.app/article/1035-how-to-change-your-icloud-password]

How to Change Your Hotmail or Outlook Password
[https://help.futureproof.app/article/1036-how-to-change-your-hotmail-or-outlook-password]

How to Change Your Email Password (for other Email Accounts)
[https://help.futureproof.app/article/1037-how-to-%D1%81hange-your-email-password-for-other-email-accounts]

Then, turn on Two-Step Verification while you're there, so your account is
harder to access even if your password is compromised again in the future.
You’ll also find how to do that by clicking the links above.

2. Be mindful of emails that mention your username, avatar, profile, or accounts
connected to the same email address
This data was collected from public profiles. It may not only lead to more spam,
but also help connect your email address with names and usernames you use on
other websites.


WHY THIS BREACH MATTERS

Even though this breach happened back in 2020, leaked data doesn't just expire.
It keeps getting bought, sold, and reused by scammers. 

And even if you've never used this exact site before, your email may have still
ended up in it through a partner, data broker, or another service behind the
scenes. 

If you've ever reused this password anywhere else, it's worth taking a minute to
secure it now.