Description

SurveyLama, a survey rewards platform, has disclosed a data breach affecting over 4.4 million users. The breach, which transpired in February, was brought to light recently when the compromised data appeared on the Have I Been Pwned (HIBP) platform. The leaked information encompasses email addresses, names, addresses, phone numbers, dates of birth, and IP addresses of users. Additionally, the breach compromised passwords stored in salted SHA-1, bcrypt, or argon2 hashes. Although these passwords are not immediately exploitable, they could be subjected to cracking attempts, potentially jeopardizing user accounts. In response to inquiries, SurveyLama stated that it has initiated a platform-wide password reset to enhance account security. Users were notified via email to reset their passwords, effectively nullifying the compromised ones. SurveyLama also disclosed that it had been made aware of a possible leak a month or two prior to its public acknowledgment. Despite these measures, SurveyLama remains uncertain about the root cause of the breach. Nevertheless, the platform has undertaken security assessments and implemented modifications to fortify its systems against future vulnerabilities. SurveyLama, owned by French company Globe Media, allows registered users to earn monetary rewards by completing surveys, with promised earnings of up to $300 per month. Overall, SurveyLama's response emphasizes a commitment to user security and mitigation of potential risks associated with the breach.