DriversRecommendedOutdated drivers can make a good PC feel brokenScan driver issues before chasing fixes manually.Scan NowOctober DealsAmazon USOctober deal check: compare before you payAmazon US: current deals, useful picks and tech finds.Check DealsSlow PC?RecommendedPC slow today? Run a repair scan before it gets worseResolve common Windows issues and optimize system performance.Scan Now×
Skip to content
The Finance Base
The Money Desk · Blog
Re:

Typeform Data Breach: What the 2018 Incident Exposed

Typeform disclosed in June 2018 that an unauthorized party accessed backups of some survey responses. Here’s what Monzo and Tasmania reported—and what remains unknown.
From TheFinanceBase Team6 min to read

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The Typeform breach was disclosed in June 2018—not a new 2026 incident. An unauthorized party accessed backups containing responses to some Typeform surveys conducted before May 3, 2018. Multiple organizations reported affected forms, but no authoritative global total of organizations or records was established. Monzo estimated that about 20,000 people might be affected; it said passwords, bank details and payment details were not exposed in its case.

What happened in the Typeform breach?

Typeform provides hosted forms and surveys. In June 2018, the company told customers that an unauthorized party had accessed backups containing survey responses. The affected material related to surveys conducted before May 3, 2018. Because organizations used the same provider to collect responses, one provider-side incident had consequences for multiple, unrelated customers.

The public accounts do not establish a specific exploit, attacker identity or complete intrusion path. The defensible description is unauthorized access to survey-response backups—not a confirmed compromise of every Typeform account or all data held by every customer. SecurityWeek’s contemporaneous report described Typeform as having identified and addressed the source of the breach, but did not provide a detailed technical postmortem.

When was it disclosed?

  • Before May 3, 2018: The affected survey-response period identified in customer notices.
  • June 29, 2018: Monzo said Typeform notified it, and Monzo published its customer notice that day.
  • Late June and early July 2018: Tasmania’s electoral authority was informed around June 30, and public reporting followed.

June 29 is the date of Monzo’s notification and public response, not an established date for when attackers first accessed the backups. Monzo’s notice and ABC News’ report on Tasmania describe those separate notifications.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

What information was exposed?

The breach did not expose one uniform dataset. The information at risk depended on the questions each organization had put in its forms and which responses were held in the affected backups.

Monzo survey responses

Monzo estimated that approximately 20,000 people might be affected. It said the most common exposure was an email address alone. Its notice also described smaller groups whose response data included combinations of personal or demographic details.

Information listed by Monzo Entries in Monzo’s breakdown
Email address only 19,213
Postcode and former bank 4,100
Twitter username 57
University 23
City 8
Age band 3
Salary band 1
Employer 1

These are the category counts Monzo published, not a verified count of unique people: categories can overlap. The total of the entries is 23,406, so it should not be used to replace Monzo’s approximate 20,000-person estimate or presented as the total for the Typeform breach. See Monzo’s breakdown for its account of the data.

Tasmanian election-related forms

Information potentially accessed included names, dates of birth, email addresses and enrolment addresses connected to people who had applied for express voting. The Tasmanian Electoral Commission later clarified that the electoral roll itself was not involved; the potentially affected information related to express-vote and non-voter-excuse forms. Its 2018–19 annual report records that distinction.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Other organizations

Contemporary reporting linked Monzo and the Tasmanian Electoral Commission to the incident, and also identified Thriva, Birdseye, HackUPC and Ocean Protocol. That is a list of organizations named in reporting, not a complete victim list. No reliable public total for affected organizations or records across all Typeform customers was established. A company’s past use of Typeform alone does not prove that its data was in the compromised backups. SecurityWeek’s report names several organizations while also discussing the service’s wider customer base.

What was reported as unaffected?

For Monzo’s affected respondents, the company said payment details, bank-account information and passwords were not exposed. It described the affected information as survey responses, rather than Monzo account credentials or access to customers’ money. Contemporary reporting also attributed statements to Typeform that passwords, payment information and data collected after May 3, 2018 were not impacted.

These are statements by the company and affected organizations, not proof that the same categories were unaffected in every customer’s separate forms. In particular, Monzo’s assurance about financial information should not be generalized into a universal finding about every organization that used Typeform.

How many people and organizations were affected?

  • Monzo respondents: Monzo estimated approximately 20,000 people could be affected. Its category counts overlap and do not establish a unique-person total.
  • Other organizations: Multiple organizations were publicly identified, but a complete authoritative list and total were not established.
  • All records across Typeform: No reliable public global count was established. The figure of 20,000 is Monzo’s estimate, not a total for every Typeform customer.

Exposure depended on whether an organization’s responses were in the affected backups and what its forms collected. It did not automatically include every Typeform customer, every person who had ever filled in a Typeform form, or surveys outside the stated period.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

How did affected organizations respond?

Monzo

Monzo contacted potentially affected customers, described the data categories, reported the incident to the UK Information Commissioner’s Office and said it would end its relationship with Typeform pending security improvements and deletion of customer data. It also said it would shorten survey-data retention with future providers. These measures illustrate why a vendor’s investigation cannot replace a customer organization’s own work to identify affected forms and respondents.

Tasmanian Electoral Commission

The Commission notified affected electors and said the electoral roll was not involved. Its later annual report said affected electors were contacted within three days. The incident concerned particular election-related forms, rather than a compromise of the roll itself.

What should someone who received a breach notice do?

  1. Read the notice for the specific form and data. The risk depends on what that organization collected; a Typeform-related notice does not by itself mean banking credentials were exposed.
  2. Contact the organization that collected the information. It can explain which form was involved, what response data was affected and whether it recommends additional action.
  3. Watch for tailored phishing and social engineering. Be cautious with unexpected messages that refer to a past survey, former bank, employer, university or election application. Verify requests through a known official channel rather than a link or number in an unsolicited message.
  4. Match precautions to the exposed fields. If the notice includes an address, date of birth or other identity attributes, consult the relevant government or identity-theft guidance for your jurisdiction. Follow any specific fraud or monitoring advice from the affected organization.

A routine password reset or credit freeze is not established as necessary for every person affected by this incident. For Monzo respondents, the company said passwords and financial details were not exposed.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What should organizations learn from the incident?

The practical lesson is to manage the information sent to form vendors as carefully as information stored in internal systems. A vendor breach can expose responses collected by many customers, while each customer still needs to know what it collected, how long it retained responses and whom it must notify.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  • Collect less. Do not put passwords, payment-card numbers, bank details, government identifiers or identity-document images into a general-purpose form unless a properly assessed system and process are designed for that purpose.
  • Set retention limits. Delete responses when the business need and applicable legal retention requirement have ended. Consider how deletion interacts with backups and ask the vendor what deletion means in practice.
  • Classify the data before choosing a tool. Decide whether a form will collect low-sensitivity feedback or personal, financial, employment or electoral information, then choose controls appropriate to that risk.
  • Review access and integrations. Limit who can view, export or administer responses, and check which connected services can receive them.
  • Ask about safeguards and evidence. Cover backup access controls, tenant separation, encryption, access logs, MFA, SSO, incident handling, deletion, subprocessors and available independent assurance.
  • Agree notification responsibilities in advance. Contracts and incident plans should specify how quickly the vendor notifies the customer, what details it provides and how the parties coordinate regulatory and respondent communications.
  • Practice the response. Keep a contact and escalation path for identifying affected forms, deciding notification obligations and communicating clearly with respondents.

Encryption is useful but not a complete guarantee: it does not establish that data remains unreadable in every circumstance, including when an attacker can access systems, keys or application-layer data. Likewise, a certification or vendor security feature is evidence to evaluate, not a substitute for data minimization, access control and an agreed incident process.

What does Typeform say about its current security controls?

Typeform’s current security documentation describes controls and processes including MFA, Enterprise SSO, access auditing, encryption, incident management and penetration testing. Its documentation also discusses shared responsibility and its handling of customer responses and subprocessors. These are Typeform’s published descriptions of its current practices; they do not provide a forensic explanation of the 2018 incident or prove that any service will be free from future risk.

Organizations assessing any hosted form provider should verify the controls, contract terms and plan-specific features that apply to their own use case rather than relying on a general security page alone.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Leave a Reply

Your email address will not be published. Required fields are marked *

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

More post from the Money Desk

  1. The Money DeskBlogTheFinanceBase09 OCT 267 minMortgage Escrow FAQs: Taxes, Insurance, Shortages, and Refunds
  2. The Money DeskBlogTheFinanceBase09 OCT 265 minHow Mortgage Escrow Accounts Work and What Homeowners Pay For
  3. The Money DeskBlogTheFinanceBase09 OCT 265 minHow to Read a Stock Chart, Volume and Market-Cap Data
Recommended PC Tool
Recommended PC Tool
Windows Errors? Fix Them Before They SpreadFree repair scan
Crashes, No Sound, or Screen Glitches?Free driver scan

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.