21 Million Users Affected by Timehop Data Breach

21 Million Users Affected by Timehop Data Breach

Timehop disclosed a security breach that has compromised the personal data, including names and emails, of its 21 million users

Timehop, a memory sharing smartphone app, disclosed a security breach that has compromised the personal data, including names and emails, of its 21 million users. Around a fifth of the affected users (4.7 million) have also had a phone number that was attached to their account breached in the attack.

Timehop is a smartphone application designed to resurface old posts from several social media accounts including Facebook, Twitter, Instagram and Google accounts as well as iCloud photos and videos.

The startup said it discovered the attack on July 4 as it was happening and was able to shut it down two hours later, but not before the data of millions was stolen.

According to the preliminary investigation of the incident, the attacker first accessed Timehop's cloud environment in December, using compromised admin credentials, and observed the system for a few days that month and then again in March and June before launching the attack on the 4th.

Timehop publically disclosed the breach in a blog post on Saturday and notified all users through the app on Monday morning. The app says no social media posts were breached during the attack, and the blog emphasizes that none of the content its service lifts from third party social networks was affected.

"With breaches happening every day, it’s nice to see an organization take steps which will help post-breach beyond the free year of credit card monitoring that has become the norm," Travis Smith, principal security researcher at Tripwire said. "Timehop took the time to understand the scope of the breach and what was impacted. This allowed them to deactivate the access keys which the attacker appeared to have been after."

While the social media posts were not affected, the keys that allow Timehop to read the posts were. Users will have to re-authenticate their social media platforms with the app in order to see their memories.

In order to protect the cloud computing environment from future attacks, the startup is implementing multifactor authentication to secure authorization and access controls on all accounts that did not previously have them.

“There is no such thing as perfect when it comes to cyber security but we are committed to protecting user data," the blog post read. "As soon as the incident was recognized we began a program of security upgrades.”

About the Author

Sydny Shepard is the Executive Editor of Campus Security & Life Safety.

Featured

  • Security Industry Association Announces the 2026 Security Megatrends

    The Security Industry Association (SIA) has identified and forecasted the 2026 Security Megatrends, which form the basis of SIA’s signature annual Security Megatrends report defining the top 10 factors influencing both near- and long-term change in the global security industry. Read Now

  • The Future of Access Control: Cloud-Based Solutions for Safer Workplaces

    Access controls have revolutionized the way we protect our people, assets and operations. Gone are the days of cumbersome keychains and the security liabilities they introduced, but it’s a mistake to think that their evolution has reached its peak. Read Now

  • A Look at AI

    Large language models (LLMs) have taken the world by storm. Within months of OpenAI launching its AI chatbot, ChatGPT, it amassed more than 100 million users, making it the fastest-growing consumer application in history. Read Now

  • First, Do No Harm: Responsibly Applying Artificial Intelligence

    It was 2022 when early LLMs (Large Language Models) brought the term “AI” into mainstream public consciousness and since then, we’ve seen security corporations and integrators attempt to develop their solutions and sales pitches around the biggest tech boom of the 21st century. However, not all “artificial intelligence” is equally suitable for security applications, and it’s essential for end users to remain vigilant in understanding how their solutions are utilizing AI. Read Now

  • Improve Incident Response With Intelligent Cloud Video Surveillance

    Video surveillance is a vital part of business security, helping institutions protect against everyday threats for increased employee, customer, and student safety. However, many outdated surveillance solutions lack the ability to offer immediate insights into critical incidents. This slows down investigations and limits how effectively teams can respond to situations, creating greater risks for the organization. Read Now

New Products

  • Camden CM-221 Series Switches

    Camden CM-221 Series Switches

    Camden Door Controls is pleased to announce that, in response to soaring customer demand, it has expanded its range of ValueWave™ no-touch switches to include a narrow (slimline) version with manual override. This override button is designed to provide additional assurance that the request to exit switch will open a door, even if the no-touch sensor fails to operate. This new slimline switch also features a heavy gauge stainless steel faceplate, a red/green illuminated light ring, and is IP65 rated, making it ideal for indoor or outdoor use as part of an automatic door or access control system. ValueWave™ no-touch switches are designed for easy installation and trouble-free service in high traffic applications. In addition to this narrow version, the CM-221 & CM-222 Series switches are available in a range of other models with single and double gang heavy-gauge stainless steel faceplates and include illuminated light rings.

  • ResponderLink

    ResponderLink

    Shooter Detection Systems (SDS), an Alarm.com company and a global leader in gunshot detection solutions, has introduced ResponderLink, a groundbreaking new 911 notification service for gunshot events. ResponderLink completes the circle from detection to 911 notification to first responder awareness, giving law enforcement enhanced situational intelligence they urgently need to save lives. Integrating SDS’s proven gunshot detection system with Noonlight’s SendPolice platform, ResponderLink is the first solution to automatically deliver real-time gunshot detection data to 911 call centers and first responders. When shots are detected, the 911 dispatching center, also known as the Public Safety Answering Point or PSAP, is contacted based on the gunfire location, enabling faster initiation of life-saving emergency protocols.

  • Unified VMS

    AxxonSoft introduces version 2.0 of the Axxon One VMS. The new release features integrations with various physical security systems, making Axxon One a unified VMS. Other enhancements include new AI video analytics and intelligent search functions, hardened cybersecurity, usability and performance improvements, and expanded cloud capabilities