We recently learned that some of our user data may have been improperly accessed. We have taken immediate action to contain and fix the issue, and we are continuing to investigate with assistance from external security experts.
The investigation, to date, indicates that the following types of information may have been involved:
Email addressDate of birth and gender (if provided)IP address upon sign up, if signed up before 2017Profile display nameAccount name and salted and cryptographically hashed passwordsResponses provided to surveys distributed in 2015 or earlierList of Paid Stories and chapter titles purchased by a userAny third-party account IDs, such as Google or Facebook. Passwords associated with third-party accounts are not stored on our systems and are unaffected.
We want to stress that Wattpad does not store plain text passwords; all Wattpad passwords are encrypted. User stories, private messages, and phone numbers were NOT part of this incident. Financial or payment information are not stored on affected systems and, based on the investigation to date, were not affected in this incident.
Although we use encryption to store passwords, as a precaution, we are taking steps to enhance the standards we use for passwords on our platform and we are recommending you change your password on Wattpad and any other third-party accounts where you use the same password.Here is a link to our Help Centre article to guide you through the process. Please note that Wattpad will never ask you for your password except to sign in to your account, and we will only do this on the Wattpad domain.