01Summary
On March 2, 2013, Evernote's security team detected unauthorized access to the company's user database. The attackers had obtained usernames, email addresses, and password hashes. Evernote stated that the passwords were protected by salted hashing, making them difficult to reverse, but forced a universal password reset as a precautionary measure. The breach was discovered by Evernote's own security monitoring systems. The prompt disclosure and forced password reset were praised as a model response to data breaches at the time.
02Background
Evernote was one of the most popular note-taking and productivity applications in 2013, with over 50 million users worldwide. The breach affected a significant portion of its global user base.
03Key revelations
- 01Even major cloud services with strong security practices can be breached.
- 02Salted password hashing mitigated but did not eliminate the risk of credential exposure.
- 03Forced universal password reset was an effective mitigation strategy.
04Technical analysis
Attackers gained access to Evernote's user database containing encrypted (salted and hashed) passwords. The specific method of initial access was not publicly disclosed. Evernote did not store passwords in plaintext and the hashing algorithm made password cracking difficult but not impossible.
- Attack vector
- Unknown (likely Web application vulnerability or credential compromise)
- Attack method
- Data Breach / Credential Theft
05Threat actor
The perpetrator(s) behind the Evernote breach remain unidentified. The attack demonstrated the persistent threat facing even well-secured cloud services.
Attribution sources
- Evernote Confirmation
- Media Reports
06Victims and impact
Countries affected
- Global
07Data exposed
Data types
- Usernames
- Email Addresses
- Password Hashes (salted)
Notable documents
- Evernote Security Notification (March 2, 2013)
08Financial damage
Primarily reputational damage and cost of forced password reset.
09Timeline
- 2013-03-02Evernote detects unauthorized access to user database; forces universal password reset.
10Reaction and fallout
Public reaction
Users were largely understanding, but the breach raised concerns about storing sensitive notes on cloud platforms.
11Legal
No specific legal action was reported against the perpetrators.
12Aftermath
Security improvements
- Evernote enhanced access controls and monitoring.
- Universal password resets became industry best practice after breaches.
13Significance and legacy
Significance
The Evernote breach was one of the largest password-related breaches of 2013, affecting 50 million users. The company's response set a standard for transparent breach disclosure.
Legacy
The incident contributed to the widespread adoption of forced password resets and transparent breach notifications as industry best practices.
14Disclosure and media
- Authentication
- Evernote official disclosure
Publishing organisations
- Evernote
15Field notes
- 01Evernote's password reset affected 50 million users simultaneously.
- 02The company's prompt disclosure was praised as a model for breach response.
16Resolution
Evernote forced a universal password reset and enhanced security monitoring.
17Sources
Official documents
- Evernote security blog post (2013)
References
- [1]Evernote security notice (2013)
- [2]Media reports (TechCrunch, The Verge)









