GFAN
HighReportedDigital services
In October 2016, GFAN suffered a data breach. 23 million accounts were affected. The exposed data includes email addresses, connection data, passwords and account identifiers. Have I Been Pwned flags this breach as unverified: its origin could not be confirmed.
- Disclosed on
- October 10, 2016
- Incident dated
- October 10, 2016
- Accounts affected
- 23M
- Sector
- Digital services
- Country
- International or undetermined
- Cause
- Undisclosed
Exposed data
- Email address
- Connection data (IP, logs)
- Password (hashed)
- Customer ID
You are only affected if you had an account or an order with this organisation.
What you can do
- Change that password — and everywhere you reused it. That is how a leak spreads to your other accounts.
- Turn on two-factor authentication on the affected accounts: a stolen password is then no longer enough.
- Expect phishing attempts quoting your name and this company. A message that knows your details is not legitimate for that reason.
- You can ask the organisation exactly what was exposed about you (right of access), and complain to the DPA if no answer comes within a month.
Sources
Entry built from Have I Been Pwned’s structured data, with no model rewriting. Spotted an error, or have a correction? Write to us and the entry will be fixed. Contact