Fall ResetAmazon USFall reset deals: check better picks before checkoutAmazon US: today's deals, useful picks and quick comparisons.Check DealsWindows FixRecommendedWindows errors stealing your time? Find the fix fastScan stability, cleanup and performance issues.Fix NowFall ResetAmazon USWork and home upgrades are worth comparing todayAmazon US: today's deals, useful picks and quick comparisons.See Picks×
Skip to content
Blog

Houzz Data Breach: What Was Exposed and What Users Should Do

By TheFinanceBase Team5 min read
Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Some links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.

The Houzz data breach was a 2018 incident disclosed in late January and early February 2019—not a newly reported 2026 breach. Houzz said an unauthorized third party obtained a file containing user data. The file may have included email addresses, profile details, IP addresses and salted password hashes. Houzz said financial information was not involved and that it had no evidence passwords were compromised, but advised users to reset passwords. For former users, the most important step now is changing any password reused on other accounts.

What happened in the Houzz breach?

Houzz said it learned that an unauthorized third party had obtained a file containing some user data. The company reported that it began an investigation, notified law enforcement and hired a security-forensics firm. Contemporary reports published the disclosure on January 31 and February 1, 2019. TechCrunch reported the disclosure, and SecurityWeek summarized the company’s account and affected data.

The public information does not establish how the third party obtained the file, exactly when it was taken, who was responsible, or whether the file was posted or sold. It is more accurate to describe this as unauthorized access to a file than to claim that a particular database was hacked or to assign a cause.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Timeline: breach date versus disclosure date

Date What it refers to
May 23, 2018 Mozilla Monitor lists this as the breach date. This is an external database record, not a date confirmed in a public Houzz forensic report.
January 31, 2019 TechCrunch reported Houzz’s disclosure.
February 1, 2019 SecurityWeek published its report.
February 4–5, 2019 ESET published follow-up coverage of the password-reset advice.
March 12, 2019 Mozilla Monitor says the incident was added to its database.

These dates describe different things: a breach date recorded by a monitoring service, news publication dates and a database-entry date. Public sources do not fully reconcile when Houzz discovered the incident or when every affected user was notified.

What information may have been exposed?

According to a copy of Houzz’s notification reproduced in a Houzz community discussion, the file may have included several categories of data:

  • Public profile details: first and last name, city, state and country, profile description, current username, and whether a profile image was present. The notice described these as information users had made public.
  • Account details: email address, user ID and previous Houzz usernames.
  • Technical and location data: IP address and city or ZIP code inferred from it, along with internal identifiers and site-country fields.
  • Password hashes: one-way password representations that Houzz said were uniquely salted for each user.
  • Facebook identifier: a public Facebook ID for users who signed in to Houzz using Facebook.

A public Facebook ID is an account identifier, not a Facebook password. The available reporting does not say that Houzz exposed Facebook credentials or access tokens, and the Houzz incident should not be conflated with separate Facebook security events.

Were passwords or financial details compromised?

Houzz said it did not believe passwords had been compromised, but password hashes were among the data that may have been exposed. A hash is not a readable plaintext password. A salt is additional data used in the hashing process; using a unique salt makes it harder to compare password hashes across accounts. But hashes are not a guarantee that passwords cannot be recovered, particularly if people chose weak passwords. Houzz did not publicly identify the hashing algorithm in the available notice, and public sources do not establish that any hashes were cracked.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Houzz recommended password resets as a precaution. That was sensible even if the company had no evidence of password compromise: users may reuse passwords, and a password that is exposed or guessed on one service can put other accounts at risk.

Houzz also said the incident did not involve financial information, including payment-card or bank-account details, or Social Security numbers. Treat that as Houzz’s stated assessment, not as an independently published forensic conclusion. The company’s account was reported by SecurityWeek and ESET’s WeLiveSecurity.

How many people were affected?

Houzz did not publicly give an exact affected-user count in the reproduced notification. Later, external breach-monitoring services and secondary reports associated the incident with roughly 49 million email addresses. That is not the same as a company-confirmed count of 49 million individual victims: an address count may not equal a count of unique people, and Houzz did not confirm that figure as its affected-user total. Mozilla Monitor’s entry provides one external record of the incident.

What former Houzz users should do now

  1. Change any reused password. If you used your old Houzz password on another service and have not changed it since the incident, replace it there. Prioritize your email account and any accounts involving money or sensitive personal information.
  2. Use a unique password for every account. A password manager can generate and store distinct passwords. It does not remove already exposed data or guarantee account recovery, but it reduces the harm from password reuse.
  3. Turn on multifactor authentication where available. This adds a verification step beyond the password and can help protect an account if a password is exposed.
  4. Check your accounts and alerts. Review important accounts for unfamiliar sign-ins, password-reset messages or other unexpected activity. A breach-monitoring alert can show that an email appears in a known dataset; it does not prove that an account was accessed or that a new breach occurred.
  5. Be alert for targeted phishing. Names, email addresses, profile details and location clues can make deceptive messages more convincing. Do not click unexpected security-email links. Open the service by typing its address or using a trusted bookmark, then use its current account settings or support channels.
  6. Secure an unused Houzz account before closing it. If you still have access and no longer need the account, use Houzz’s current website or support information to check account-closure options. Don’t rely on a password-reset link or help-page path from 2019 as a current route.

If you receive a Houzz security message today, its arrival alone does not show that a new breach has taken place. Monitoring services may report old incidents, and users have also described later account-security messages that were separate from the original breach notification. Verify unexpected messages through Houzz’s site or support rather than trusting links in the message.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What remains unknown

Public reporting and the reproduced notice do not resolve the method of access, the precise date the file was obtained, the exact number of affected accounts, the identity of the third party, whether the file was publicly distributed, or whether anyone misused the information. The available evidence supports concern about privacy, phishing and reused credentials; it does not establish that identity theft or account takeover resulted from this incident.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Written by TheFinanceBase Team

The Team behind TheFinanceBase.

Add your note

Your email address will not be published. Required fields are marked *

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Recommended PC Tool
Recommended PC Tool
Crashes, No Sound, or Screen Glitches?Free driver scan
Windows Errors? Fix Them Before They SpreadFree repair scan

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.