Search TorNews

Find cybersecurity news, guides, and research articles

Popular searches:

Home » News » Data Breaches » 10 Million Stripchat Records from 2021 Breach Resurface on Cybercrime Forum

10 Million Stripchat Records from 2021 Breach Resurface on Cybercrime Forum

Last updated:August 25, 2026
Human Written
  • A threat actor shared what they described as a database they copied from a previous Stripchat breach on a cybercrime forum.

  • The actor claims that it holds over 10 million records, including emails, usernames, IP addresses, etc.

  • Currently, there’s no sign of a new Stripchat breach in 2026. This just looks like someone reposting the old breach data.

10 Million Stripchat Records from 2021 Breach Resurface on Cybercrime Forum

A Stripchat database from a 2021 exposure has resurfaced on a cybercrime forum. The user is offering a partial copy as a free download.

The post claims the data came from the earlier Stripchat exposure and covers over 10 million records. The exposed data includes email addresses, usernames and IP addresses of Stripchat. A sample also appears to show account and technical details.

There is no clear evidence of a new Stripchat intrusion in 2026. The post links the data to the November 2021 exposure. That matches records from Have I Been Pwned and Mozilla Monitor. The new activity still matters. Old breach data can gain new value when more criminals get access to it.

Details of the Original Stripchat Data Leak

The Stripchat data leak was originally reported in November 2021. Camparitech head of security research Bob Diachenko said he stumbled upon an open Elasticsearch database tied to Stripchat online. This wasn’t just a small leak. Nearly 200 million records across several databases were floating around.

This breach exposed sensitive personal data, email addresses, user names, and IPs. Other records contained user activity, account creation times and payment-related details. Reports also found data linked to models on the platform.

Diachenko alerted Stripchat on November 5, 2021. Comparitech said the company secured the database two days later. The reported total counted records across several databases. It did not count unique people. That helps explain why later breach trackers show a smaller account count.

More than 10 Million Accounts Appear in Breach Trackers

Have I Been Pwned data matched the researchers’ report. The platform lists 10,001,355 Stripchat accounts that were exposed. The entry shows the leak occurred in November 2021.

Also, Have I Been Pawned also notes that over 10 million Stripchat records showed up on a hacking forum in June 2022. The records contained the same set of information, usernames, email addresses, IP addresses, the works.

Mozilla Monitor also logged the exposure, it says the breach occurred on November 5, 2021. It lists the same three types of exposed information. These records help explain the “10M+” claim. But that figure does not prove the current copy contains 10 million unique people.

The new post calls the file a partial copy. That means the size of the file may differ from the full historical dataset.

Why Old Breach Data can Still cause Harm

A repost can put old information in front of a new group of criminals. Attackers can match an old email address with data from a newer breach. They can build a fuller profile of a target.

That can make phishing messages more believable. A criminal may know an old Stripchat username, email address or IP address. They can match it with details from other sources.

The sensitive nature of the service creates another risk. Criminals may use old membership data to threaten or shame victims. They could demand money while claiming to know a person’s activity.

An exposed email address can fuel more spam and targeted scams. And if people reuse passwords, the risk can be higher. However, the known Stripchat data does not establish that current passwords were exposed.

A similar case involved an alleged University of India’s Delhi breach, with student and applicant data offered for $450 on a dark web forum. However, the university has not confirmed the breach, and the data remains unverified, warranting caution.

The 2026 Post Does not Show a New Stripchat Hack

This is the key point when assessing the latest alert. The current forum activity appears to involve redistribution, not a fresh attack on Stripchat. The post points to the older incident. The listed data also matches the known 2021 exposure.

That does not prove that Stripchat has had no security problems since 2021. It only means the evidence found for this report does not establish a new 2026 compromise. That distinction matters to companies, researchers and users.

Dark web alerts can appear to be from a new breach even though the data is from an old database. So it’s best to take action only after determining the age of the database, the categories of data, and the origin of the files.

What Stripchat Users Should do

Those who used Stripchat during the time of the 2021 breach should consider their previous account credentials as vulnerable. They should keep an eye out for emails referring to Stripchat or saying that they have private information regarding users’ online activities. These people should not click any unusual links or attachments.

Users should also avoid using previous passwords. It will help them reduce the risk of further damage in case there is a breach on one service. Two-factor authentication provides an extra security level.

The person receiving extortion demands should not take it for granted that the sender has access to their new account. A criminal may only have old breach data.

The latest forum post is a reminder that old data breaches can stay relevant for many years after the incidents. Take the Stripchat incident, it happened over five years ago, but the data is still resurfacing online.

While the evidence points to someone recycling old data, people still need to apply caution. That data is still out there, and criminals can use it to carry out all kinds of scams. The risk of scams and other privacy issues for the victims whose information is already circulating online remains a prime concern.

Share this article

About the Author

Memchick E

Memchick E

Digital Privacy Journalist

Memchick is a digital privacy journalist who investigates how technology and policy impact personal freedom. Her work explores surveillance capitalism, encryption laws, and the real-world consequences of data leaks. She is driven by a mission to demystify digital rights and empower readers with the knowledge to protect their anonymity online.

View all posts by Memchick E >
Comments (0)

No comments.