Free tools Windows power users keep installed
One-click scans. No signup required.
The Typeform breach was disclosed in June 2018—not a new 2026 incident. An unauthorized party accessed backups containing responses to some Typeform surveys conducted before May 3, 2018. Multiple organizations reported affected forms, but no authoritative global total of organizations or records was established. Monzo estimated that about 20,000 people might be affected; it said passwords, bank details and payment details were not exposed in its case.
What happened in the Typeform breach?
Typeform provides hosted forms and surveys. In June 2018, the company told customers that an unauthorized party had accessed backups containing survey responses. The affected material related to surveys conducted before May 3, 2018. Because organizations used the same provider to collect responses, one provider-side incident had consequences for multiple, unrelated customers.
The public accounts do not establish a specific exploit, attacker identity or complete intrusion path. The defensible description is unauthorized access to survey-response backups—not a confirmed compromise of every Typeform account or all data held by every customer. SecurityWeek’s contemporaneous report described Typeform as having identified and addressed the source of the breach, but did not provide a detailed technical postmortem.
When was it disclosed?
- Before May 3, 2018: The affected survey-response period identified in customer notices.
- June 29, 2018: Monzo said Typeform notified it, and Monzo published its customer notice that day.
- Late June and early July 2018: Tasmania’s electoral authority was informed around June 30, and public reporting followed.
June 29 is the date of Monzo’s notification and public response, not an established date for when attackers first accessed the backups. Monzo’s notice and ABC News’ report on Tasmania describe those separate notifications.
#1 Best Overall
What information was exposed?
The breach did not expose one uniform dataset. The information at risk depended on the questions each organization had put in its forms and which responses were held in the affected backups.
Monzo survey responses
Monzo estimated that approximately 20,000 people might be affected. It said the most common exposure was an email address alone. Its notice also described smaller groups whose response data included combinations of personal or demographic details.
| Information listed by Monzo | Entries in Monzo’s breakdown |
|---|---|
| Email address only | 19,213 |
| Postcode and former bank | 4,100 |
| Twitter username | 57 |
| University | 23 |
| City | 8 |
| Age band | 3 |
| Salary band | 1 |
| Employer | 1 |
These are the category counts Monzo published, not a verified count of unique people: categories can overlap. The total of the entries is 23,406, so it should not be used to replace Monzo’s approximate 20,000-person estimate or presented as the total for the Typeform breach. See Monzo’s breakdown for its account of the data.
Tasmanian election-related forms
Information potentially accessed included names, dates of birth, email addresses and enrolment addresses connected to people who had applied for express voting. The Tasmanian Electoral Commission later clarified that the electoral roll itself was not involved; the potentially affected information related to express-vote and non-voter-excuse forms. Its 2018–19 annual report records that distinction.
Rank #2
Other organizations
Contemporary reporting linked Monzo and the Tasmanian Electoral Commission to the incident, and also identified Thriva, Birdseye, HackUPC and Ocean Protocol. That is a list of organizations named in reporting, not a complete victim list. No reliable public total for affected organizations or records across all Typeform customers was established. A company’s past use of Typeform alone does not prove that its data was in the compromised backups. SecurityWeek’s report names several organizations while also discussing the service’s wider customer base.
What was reported as unaffected?
For Monzo’s affected respondents, the company said payment details, bank-account information and passwords were not exposed. It described the affected information as survey responses, rather than Monzo account credentials or access to customers’ money. Contemporary reporting also attributed statements to Typeform that passwords, payment information and data collected after May 3, 2018 were not impacted.
These are statements by the company and affected organizations, not proof that the same categories were unaffected in every customer’s separate forms. In particular, Monzo’s assurance about financial information should not be generalized into a universal finding about every organization that used Typeform.
How many people and organizations were affected?
- Monzo respondents: Monzo estimated approximately 20,000 people could be affected. Its category counts overlap and do not establish a unique-person total.
- Other organizations: Multiple organizations were publicly identified, but a complete authoritative list and total were not established.
- All records across Typeform: No reliable public global count was established. The figure of 20,000 is Monzo’s estimate, not a total for every Typeform customer.
Exposure depended on whether an organization’s responses were in the affected backups and what its forms collected. It did not automatically include every Typeform customer, every person who had ever filled in a Typeform form, or surveys outside the stated period.
The Tool Desk
Outbyte Driver Updater FREEFix the driver behind crashes, sound loss and screen glitchesFind Drivers →Outbyte PC Repair FREEClear out junk files and repair common Windows errorsFree Scan →How did affected organizations respond?
Monzo
Monzo contacted potentially affected customers, described the data categories, reported the incident to the UK Information Commissioner’s Office and said it would end its relationship with Typeform pending security improvements and deletion of customer data. It also said it would shorten survey-data retention with future providers. These measures illustrate why a vendor’s investigation cannot replace a customer organization’s own work to identify affected forms and respondents.
Tasmanian Electoral Commission
The Commission notified affected electors and said the electoral roll was not involved. Its later annual report said affected electors were contacted within three days. The incident concerned particular election-related forms, rather than a compromise of the roll itself.
What should someone who received a breach notice do?
- Read the notice for the specific form and data. The risk depends on what that organization collected; a Typeform-related notice does not by itself mean banking credentials were exposed.
- Contact the organization that collected the information. It can explain which form was involved, what response data was affected and whether it recommends additional action.
- Watch for tailored phishing and social engineering. Be cautious with unexpected messages that refer to a past survey, former bank, employer, university or election application. Verify requests through a known official channel rather than a link or number in an unsolicited message.
- Match precautions to the exposed fields. If the notice includes an address, date of birth or other identity attributes, consult the relevant government or identity-theft guidance for your jurisdiction. Follow any specific fraud or monitoring advice from the affected organization.
A routine password reset or credit freeze is not established as necessary for every person affected by this incident. For Monzo respondents, the company said passwords and financial details were not exposed.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.What should organizations learn from the incident?
The practical lesson is to manage the information sent to form vendors as carefully as information stored in internal systems. A vendor breach can expose responses collected by many customers, while each customer still needs to know what it collected, how long it retained responses and whom it must notify.
Quick wins for a faster PC:
Clear out junk files and repair common Windows errorsFree Scan →Scan for outdated or missing drivers - takes under a minuteDriver Scan →- Collect less. Do not put passwords, payment-card numbers, bank details, government identifiers or identity-document images into a general-purpose form unless a properly assessed system and process are designed for that purpose.
- Set retention limits. Delete responses when the business need and applicable legal retention requirement have ended. Consider how deletion interacts with backups and ask the vendor what deletion means in practice.
- Classify the data before choosing a tool. Decide whether a form will collect low-sensitivity feedback or personal, financial, employment or electoral information, then choose controls appropriate to that risk.
- Review access and integrations. Limit who can view, export or administer responses, and check which connected services can receive them.
- Ask about safeguards and evidence. Cover backup access controls, tenant separation, encryption, access logs, MFA, SSO, incident handling, deletion, subprocessors and available independent assurance.
- Agree notification responsibilities in advance. Contracts and incident plans should specify how quickly the vendor notifies the customer, what details it provides and how the parties coordinate regulatory and respondent communications.
- Practice the response. Keep a contact and escalation path for identifying affected forms, deciding notification obligations and communicating clearly with respondents.
Encryption is useful but not a complete guarantee: it does not establish that data remains unreadable in every circumstance, including when an attacker can access systems, keys or application-layer data. Likewise, a certification or vendor security feature is evidence to evaluate, not a substitute for data minimization, access control and an agreed incident process.
What does Typeform say about its current security controls?
Typeform’s current security documentation describes controls and processes including MFA, Enterprise SSO, access auditing, encryption, incident management and penetration testing. Its documentation also discusses shared responsibility and its handling of customer responses and subprocessors. These are Typeform’s published descriptions of its current practices; they do not provide a forensic explanation of the 2018 incident or prove that any service will be free from future risk.
- Typeform security documentation
- How Typeform says it handles form data
- Typeform’s subprocessor information
Organizations assessing any hosted form provider should verify the controls, contract terms and plan-specific features that apply to their own use case rather than relying on a general security page alone.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




