EARF
United States Flag
United StatesNorth America
Japan Flag
JapanAsia
Italy Flag
ItalyEurope
Netherlands Flag
NetherlandsEurope
United Kingdom Flag
United KingdomEurope
EARFSTAGE
EARFSTAGEFestivals and live sets
METAR | EARF
EARFWeatherLive weather stations
EARFWiki
EARFWikiCountries and public records
EARFguessGuess where on Earth
/data-breach/evernote-breach-2013
314/430

File EL-0117HighResolvedData Breach / Credential Theft

Evernote Data Breach (2013)

Also filed as Evernote User Credential Breach · Evernote Account Compromise

In March 2013, Evernote announced a data breach affecting approximately 50 million users. Attackers gained access to user account information including usernames, email addresses, and hashed passwords. Evernote forced a universal password reset for all users.

  • #evernote
  • #data-breach
  • #credential-theft
  • #password-reset
  • #2013
  • #productivity
Notoriety7/10
Event
2 Mar 2013
Disclosed
2 Mar 2013
Target
Evernote Corporation
Scale
50.0M people
Status
Resolved

01Summary

On March 2, 2013, Evernote's security team detected unauthorized access to the company's user database. The attackers had obtained usernames, email addresses, and password hashes. Evernote stated that the passwords were protected by salted hashing, making them difficult to reverse, but forced a universal password reset as a precautionary measure. The breach was discovered by Evernote's own security monitoring systems. The prompt disclosure and forced password reset were praised as a model response to data breaches at the time.

02Background

Evernote was one of the most popular note-taking and productivity applications in 2013, with over 50 million users worldwide. The breach affected a significant portion of its global user base.

03Key revelations

  1. 01Even major cloud services with strong security practices can be breached.
  2. 02Salted password hashing mitigated but did not eliminate the risk of credential exposure.
  3. 03Forced universal password reset was an effective mitigation strategy.

04Technical analysis

Attackers gained access to Evernote's user database containing encrypted (salted and hashed) passwords. The specific method of initial access was not publicly disclosed. Evernote did not store passwords in plaintext and the hashing algorithm made password cracking difficult but not impossible.

Attack vector
Unknown (likely Web application vulnerability or credential compromise)
Attack method
Data Breach / Credential Theft

05Threat actor

The perpetrator(s) behind the Evernote breach remain unidentified. The attack demonstrated the persistent threat facing even well-secured cloud services.

Attribution sources

  • Evernote Confirmation
  • Media Reports

06Victims and impact

Countries affected

  • Global

07Data exposed

Data types

  • Usernames
  • Email Addresses
  • Password Hashes (salted)

Notable documents

  • Evernote Security Notification (March 2, 2013)

08Financial damage

Primarily reputational damage and cost of forced password reset.

09Timeline

  1. 2013-03-02Evernote detects unauthorized access to user database; forces universal password reset.

10Reaction and fallout

Public reaction

Users were largely understanding, but the breach raised concerns about storing sensitive notes on cloud platforms.

11Legal

No specific legal action was reported against the perpetrators.

12Aftermath

Security improvements

  • Evernote enhanced access controls and monitoring.
  • Universal password resets became industry best practice after breaches.

13Significance and legacy

Significance

The Evernote breach was one of the largest password-related breaches of 2013, affecting 50 million users. The company's response set a standard for transparent breach disclosure.

Legacy

The incident contributed to the widespread adoption of forced password resets and transparent breach notifications as industry best practices.

14Disclosure and media

Authentication
Evernote official disclosure

Publishing organisations

  • Evernote

15Field notes

  1. 01Evernote's password reset affected 50 million users simultaneously.
  2. 02The company's prompt disclosure was praised as a model for breach response.

16Resolution

Evernote forced a universal password reset and enhanced security monitoring.

17Sources

Official documents

  • Evernote security blog post (2013)

References

  1. [1]Evernote security notice (2013)
  2. [2]Media reports (TechCrunch, The Verge)
Fact sheetEL-0117

Dates

Event
2 Mar 2013
Started
2 Mar 2013
Ended
2 Mar 2013
Duration
3 days
Discovered
2 Mar 2013
Disclosed
2 Mar 2013
Resolved
4 Mar 2013
Ongoing
No

Target

Organisation
Evernote Corporation
Type
Corporation
Sector
Technology / Productivity Software
Country
United States

Actor

Motivation
Unknown (likely credential theft for resale or account takeover).
Attribution
Low
Arrested
No
Convicted
No

Data

People
50,000,000
Records
50,000,000
Volume
50 million user records
Sensitivity
Confidential
Published
No
Sold (dark web)
Yes

EARFLeaks documents publicly known security incidents. It does not host, store or distribute leaked data.

© 2026 EARF. All rights reserved.