The Evite data breach affected a significant number of users, exposing personal information that can be used for identity theft, phishing, and fraud. If you've ever had an account or relationship with Evite, it's worth checking whether your data was involved.

What Happened

Evite, the online invitation and social planning service, was breached in 2013, though the breach was not discovered and disclosed until 2019 when the stolen data appeared for sale online. The database was widely circulated, with reports citing around 101 million records, though the number of unique user accounts was estimated to be closer to 10 million.

What Data Was Exposed

The exposed data included names, email addresses, dates of birth, phone numbers (where provided), mailing addresses, and passwords for accounts created before the breach. Passwords for accounts created after Evite upgraded its security in 2013 were not affected.

Why This Still Matters

Even breaches from years ago remain a risk today. Stolen data is sold, traded, and reused indefinitely. Credentials from old breaches fuel credential stuffing attacks — automated attempts to reuse your email and password combination on other sites. If you reused a password anywhere, one old breach can compromise several current accounts.

How to Check If You Were Affected

Use our free breach checker below — enter your email and we'll scan it against known breach databases instantly, no signup required.

What to Do If You Were Affected

👉 Check your own exposure in 30 seconds → scan your email free.

Frequently Asked Questions

When did the Evite data breach happen?

The underlying breach occurred in 2013, but it went undetected for six years. Evite confirmed the incident and notified users in April 2019 after the stolen data was found for sale online.

What data was stolen in the Evite breach?

Names, email addresses, dates of birth, phone numbers, mailing addresses, and passwords (for accounts predating a 2013 security upgrade) were exposed. Evite stated payment information was not affected.

How do I check if my Evite account was affected?

Use the free checker at Scan My Shadow with your email address. Given the age of this breach, if your email appears, change any old passwords you may have reused since 2013.

Why did it take Evite six years to discover the breach?

Evite has not published detailed technical findings on why detection took so long, which is a reminder that breach discovery timelines vary significantly and some companies do not have real-time intrusion detection in place.

Is old breach data like this still dangerous?

Yes. Even years-old data like names, birthdates, and email addresses remains useful to scammers for identity theft, phishing, and account-recovery social engineering attacks.

Sources

Related Reading