The Tool Desk
Outbyte PC Repair FREEClear out junk files and repair common Windows errorsFree Scan →Outbyte Driver Updater FREEFix the driver behind crashes, sound loss and screen glitchesFind Drivers →Some links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.
The Houzz data breach was a 2018 incident disclosed in late January and early February 2019—not a newly reported 2026 breach. Houzz said an unauthorized third party obtained a file containing user data. The file may have included email addresses, profile details, IP addresses and salted password hashes. Houzz said financial information was not involved and that it had no evidence passwords were compromised, but advised users to reset passwords. For former users, the most important step now is changing any password reused on other accounts.
What happened in the Houzz breach?
Houzz said it learned that an unauthorized third party had obtained a file containing some user data. The company reported that it began an investigation, notified law enforcement and hired a security-forensics firm. Contemporary reports published the disclosure on January 31 and February 1, 2019. TechCrunch reported the disclosure, and SecurityWeek summarized the company’s account and affected data.
The public information does not establish how the third party obtained the file, exactly when it was taken, who was responsible, or whether the file was posted or sold. It is more accurate to describe this as unauthorized access to a file than to claim that a particular database was hacked or to assign a cause.
Free tools Windows power users keep installed
One-click scans. No signup required.
Timeline: breach date versus disclosure date
| Date | What it refers to |
|---|---|
| May 23, 2018 | Mozilla Monitor lists this as the breach date. This is an external database record, not a date confirmed in a public Houzz forensic report. |
| January 31, 2019 | TechCrunch reported Houzz’s disclosure. |
| February 1, 2019 | SecurityWeek published its report. |
| February 4–5, 2019 | ESET published follow-up coverage of the password-reset advice. |
| March 12, 2019 | Mozilla Monitor says the incident was added to its database. |
These dates describe different things: a breach date recorded by a monitoring service, news publication dates and a database-entry date. Public sources do not fully reconcile when Houzz discovered the incident or when every affected user was notified.
#1 Best Overall
What information may have been exposed?
According to a copy of Houzz’s notification reproduced in a Houzz community discussion, the file may have included several categories of data:
- Public profile details: first and last name, city, state and country, profile description, current username, and whether a profile image was present. The notice described these as information users had made public.
- Account details: email address, user ID and previous Houzz usernames.
- Technical and location data: IP address and city or ZIP code inferred from it, along with internal identifiers and site-country fields.
- Password hashes: one-way password representations that Houzz said were uniquely salted for each user.
- Facebook identifier: a public Facebook ID for users who signed in to Houzz using Facebook.
A public Facebook ID is an account identifier, not a Facebook password. The available reporting does not say that Houzz exposed Facebook credentials or access tokens, and the Houzz incident should not be conflated with separate Facebook security events.
Were passwords or financial details compromised?
Houzz said it did not believe passwords had been compromised, but password hashes were among the data that may have been exposed. A hash is not a readable plaintext password. A salt is additional data used in the hashing process; using a unique salt makes it harder to compare password hashes across accounts. But hashes are not a guarantee that passwords cannot be recovered, particularly if people chose weak passwords. Houzz did not publicly identify the hashing algorithm in the available notice, and public sources do not establish that any hashes were cracked.
PC Slower Than It Used to Be?
A free scan shows the junk files, broken settings and background clutter dragging Windows down - then fixes them in one click.Free scan · Windows 10 & 11Outdated Drivers Are Slowing You Down
One free scan finds every outdated or missing driver and matches the right update for your exact hardware.Free scan · exact hardware matchHouzz recommended password resets as a precaution. That was sensible even if the company had no evidence of password compromise: users may reuse passwords, and a password that is exposed or guessed on one service can put other accounts at risk.
Houzz also said the incident did not involve financial information, including payment-card or bank-account details, or Social Security numbers. Treat that as Houzz’s stated assessment, not as an independently published forensic conclusion. The company’s account was reported by SecurityWeek and ESET’s WeLiveSecurity.
How many people were affected?
Houzz did not publicly give an exact affected-user count in the reproduced notification. Later, external breach-monitoring services and secondary reports associated the incident with roughly 49 million email addresses. That is not the same as a company-confirmed count of 49 million individual victims: an address count may not equal a count of unique people, and Houzz did not confirm that figure as its affected-user total. Mozilla Monitor’s entry provides one external record of the incident.
What former Houzz users should do now
- Change any reused password. If you used your old Houzz password on another service and have not changed it since the incident, replace it there. Prioritize your email account and any accounts involving money or sensitive personal information.
- Use a unique password for every account. A password manager can generate and store distinct passwords. It does not remove already exposed data or guarantee account recovery, but it reduces the harm from password reuse.
- Turn on multifactor authentication where available. This adds a verification step beyond the password and can help protect an account if a password is exposed.
- Check your accounts and alerts. Review important accounts for unfamiliar sign-ins, password-reset messages or other unexpected activity. A breach-monitoring alert can show that an email appears in a known dataset; it does not prove that an account was accessed or that a new breach occurred.
- Be alert for targeted phishing. Names, email addresses, profile details and location clues can make deceptive messages more convincing. Do not click unexpected security-email links. Open the service by typing its address or using a trusted bookmark, then use its current account settings or support channels.
- Secure an unused Houzz account before closing it. If you still have access and no longer need the account, use Houzz’s current website or support information to check account-closure options. Don’t rely on a password-reset link or help-page path from 2019 as a current route.
If you receive a Houzz security message today, its arrival alone does not show that a new breach has taken place. Monitoring services may report old incidents, and users have also described later account-security messages that were separate from the original breach notification. Verify unexpected messages through Houzz’s site or support rather than trusting links in the message.
What remains unknown
Public reporting and the reproduced notice do not resolve the method of access, the precise date the file was obtained, the exact number of affected accounts, the identity of the third party, whether the file was publicly distributed, or whether anyone misused the information. The available evidence supports concern about privacy, phishing and reused credentials; it does not establish that identity theft or account takeover resulted from this incident.
Quick Recap
Best Value
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

