Cyber Security News

Flickr Confirms Data Breach – 35 million Users Data at Risk

Flickr has disclosed a potential data breach stemming from a vulnerability in a third-party email service provider’s system.

The incident, reported on February 5, 2026, may have exposed data for some of its 35 million monthly users, though the exact number affected remains undisclosed.

Flickr alerted affected users via email about the flaw discovered on February 5, 2026. The vulnerability in the unnamed provider’s system potentially allowed unauthorized access to Flickr member information within hours before it was shut down. No evidence suggests a broader compromise, as the company acted swiftly upon notification.

Potentially accessed data includes usernames, email addresses, account types, IP addresses, general location data based on Flickr addresses, and user activity on the platform.

Notice to Users (Source: Flickr)

Critically, passwords, payment card numbers, and other financial details were not involved. This limits immediate risks like account takeovers but raises concerns for phishing or doxxing.

The company disabled access to the vulnerable endpoint and demanded a full investigation from the provider. Flickr strengthened security procedures with third-party vendors and notified relevant data protection authorities. Users received personalized notices urging vigilance against phishing emails referencing their accounts.

Owned by SmugMug since 2018, Flickr hosts over 28 billion photos and videos from amateur and professional photographers.

With 35 million monthly users and 800 million page views, it remains a key archive for geotagged media. Past incidents include a 2023 DDoS claim by Anonymous Sudan, but no confirmed data leaks then.

Affected individuals should review their account settings for any changes and update their passwords, especially if they are reused elsewhere. Enable two-factor authentication and monitor for suspicious emails. Flickr never requests credentials via email. Tools like Have I Been Pwned can check for broader exposures, though this event is too recent for listings.

This breach highlights third-party risks in photo-sharing ecosystems, where metadata like IPs and locations amplifies privacy threats. As regulators scrutinize vendor oversight, Flickr’s quick disclosure aligns with GDPR and CCPA norms.

No public blog or press release has appeared yet, relying instead on direct notifications. Cybersecurity experts anticipate phishing spikes targeting Flickr’s creative community.

The episode underscores ongoing supply-chain vulnerabilities, even for legacy platforms. Flickr apologized for the concern and committed to enhanced monitoring. Users are advised to stay proactive amid rising 2026 breach notifications.

Follow us on Google News, LinkedIn, and X for daily cybersecurity updates. Contact us to feature your stories.

Guru Baran

Gurubaran KS is a cybersecurity analyst, and Journalist with a strong focus on emerging threats and digital defense strategies. He is the Co-Founder and Editor-in-Chief of Cyber Security News, where he leads editorial coverage on global cybersecurity developments.

Recent Posts

Google Chrome 153 Update Fixes 42 Security Flaws, Including 3 Critical Ones

Google has released an important Chrome 153 security update that fixes 42 vulnerabilities across the…

4 hours ago

CISA and NIST Release Technical Checklist for Safeguarding Identity Tokens From Theft and Misuse

The Cybersecurity and Infrastructure Security Agency (CISA) and the National Institute of Standards and Technology…

14 hours ago

CISA Shares 17 Techniques Used by Hackers to Compromise Active Directory Environments

CISA and five international cybersecurity agencies have released detailed guidance describing 17 common techniques hackers…

15 hours ago

Apple Rolls Out Massive Security Update Fixing 273 Vulnerabilities Across Its Devices

Apple has released one of its largest coordinated security rollouts, addressing 273 distinct critical vulnerabilities…

15 hours ago

How to Keep Malware’s Rotating Infrastructure From Becoming a Detection Gap

You can’t detect today's attacks with yesterday’s threat intelligence; that’s how you could briefly formulate…

15 hours ago

Microsoft Bans Its AI Models From Launching Cyberattacks or Escalating Their Own Access

Microsoft has published a draft Humanist AI Code of Conduct that would prohibit its in-house…

15 hours ago