21 Million Users Affected by Timehop Data Breach

21 Million Users Affected by Timehop Data Breach

Timehop disclosed a security breach that has compromised the personal data, including names and emails, of its 21 million users

Timehop, a memory sharing smartphone app, disclosed a security breach that has compromised the personal data, including names and emails, of its 21 million users. Around a fifth of the affected users (4.7 million) have also had a phone number that was attached to their account breached in the attack.

Timehop is a smartphone application designed to resurface old posts from several social media accounts including Facebook, Twitter, Instagram and Google accounts as well as iCloud photos and videos.

The startup said it discovered the attack on July 4 as it was happening and was able to shut it down two hours later, but not before the data of millions was stolen.

According to the preliminary investigation of the incident, the attacker first accessed Timehop's cloud environment in December, using compromised admin credentials, and observed the system for a few days that month and then again in March and June before launching the attack on the 4th.

Timehop publically disclosed the breach in a blog post on Saturday and notified all users through the app on Monday morning. The app says no social media posts were breached during the attack, and the blog emphasizes that none of the content its service lifts from third party social networks was affected.

"With breaches happening every day, it’s nice to see an organization take steps which will help post-breach beyond the free year of credit card monitoring that has become the norm," Travis Smith, principal security researcher at Tripwire said. "Timehop took the time to understand the scope of the breach and what was impacted. This allowed them to deactivate the access keys which the attacker appeared to have been after."

While the social media posts were not affected, the keys that allow Timehop to read the posts were. Users will have to re-authenticate their social media platforms with the app in order to see their memories.

In order to protect the cloud computing environment from future attacks, the startup is implementing multifactor authentication to secure authorization and access controls on all accounts that did not previously have them.

“There is no such thing as perfect when it comes to cyber security but we are committed to protecting user data," the blog post read. "As soon as the incident was recognized we began a program of security upgrades.”

About the Author

Sydny Shepard is the Executive Editor of Campus Security & Life Safety.

Featured

  • Security Industry Embraces Mobile Credentials, Biometrics and AI, New Trends Report From HID Finds

    As organizations navigate an increasingly complex threat landscape, security leaders are making strategic shifts toward unified platforms and emerging technologies, according to the newly released 2025 State of Security and Identity Report from HID. The comprehensive study gathered responses from 1,800 partners, end users, and security and IT personnel worldwide, and reveals a significant transformation in how businesses are approaching security, with mobile credentials and artificial intelligence emerging as key drivers of innovation. Read Now

  • UK’s NHS Hospital Transforms Security with Edge-processing Camera System

    i-PRO Co., Ltd.,(formerly Panasonic Security), a manufacturer of edge computing cameras for security and public safety, recently announced that a leading teaching hospital in Northeast England, has enhanced its security infrastructure with i-PRO X-Series cameras integrated with Milestone’s XProtect Video Management Software (VMS). Read Now

  • Gun Violence Report Finds Retail Spaces, K-12 Schools Most Targeted

    ZeroEyes, the creators of the only AI-based gun detection video analytics platform that holds the U.S. Department of Homeland Security SAFETY Act Designation, today announced the release of its annual Gun Violence Report, offering a deep dive into the landscape of gun-related incidents across the United States. This analysis extends beyond mass fatality events, providing a more nuanced understanding of when, where, and why shootings occur. Read Now

  • Agentic AI Will Revolutionize Cybercrime in 2025 According to New Report

    Malwarebytes, a provider in real-time cyber protection, recently released its 2025 State of Malware report, which reveals insight into the emergence of agentic artificial intelligence (AI), plus the year’s most prominent threats and cybercrime tactics. The report details a significant uptick in the number of known ransomware attacks, the total value of ransoms paid in 2024, and how IT teams can address them. Read Now

New Products

  • Hanwha QNO-7012R

    Hanwha QNO-7012R

    The Q Series cameras are equipped with an Open Platform chipset for easy and seamless integration with third-party systems and solutions, and analog video output (CVBS) support for easy camera positioning during installation. A suite of on-board intelligent video analytics covers tampering, directional/virtual line detection, defocus detection, enter/exit, and motion detection.

  • ComNet CNGE6FX2TX4PoE

    The ComNet cost-efficient CNGE6FX2TX4PoE is a six-port switch that offers four Gbps TX ports that support the IEEE802.3at standard and provide up to 30 watts of PoE to PDs. It also has a dedicated FX/TX combination port as well as a single FX SFP to act as an additional port or an uplink port, giving the user additional options in managing network traffic. The CNGE6FX2TX4PoE is designed for use in unconditioned environments and typically used in perimeter surveillance.

  • Mobile Safe Shield

    Mobile Safe Shield

    SafeWood Designs, Inc., a manufacturer of patented bullet resistant products, is excited to announce the launch of the Mobile Safe Shield. The Mobile Safe Shield is a moveable bullet resistant shield that provides protection in the event of an assailant and supplies cover in the event of an active shooter. With a heavy-duty steel frame, quality castor wheels, and bullet resistant core, the Mobile Safe Shield is a perfect addition to any guard station, security desks, courthouses, police stations, schools, office spaces and more. The Mobile Safe Shield is incredibly customizable. Bullet resistant materials are available in UL 752 Levels 1 through 8 and include glass, white board, tack board, veneer, and plastic laminate. Flexibility in bullet resistant materials allows for the Mobile Safe Shield to blend more with current interior décor for a seamless design aesthetic. Optional custom paint colors are also available for the steel frame.