Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
third-party-vendor-breachbreach-disclosure-notificationmass-credential-exposurephishing-campaign-intelligence

Flickr Discloses Potential Data Exposure via Third-Party Email Service Provider

Updated 3mo agoFirst seen Feb 6, 20268 sources

Flickr notified users of a potential data breach after discovering a vulnerability in a third-party email service provider system that may have enabled unauthorized access to some member information. Flickr said it was alerted to the flaw on February 5, 2026 and disabled access to the affected system within hours. The company did not name the provider or disclose how many users were impacted, but stated that exposed data may include real names/usernames, email addresses, account types, IP addresses, general location data, and account activity.

Flickr stated that passwords and payment card data were not compromised, reducing immediate risk of direct account takeover but increasing risk of phishing and targeted social engineering using the exposed profile and activity details. Users were advised to review account settings for unexpected changes and to be cautious of messages referencing their Flickr accounts, with Flickr emphasizing it will not request passwords via email. Separately, Substack reported a different breach involving unauthorized access to limited user data and dark web leak claims; it is not connected to the Flickr incident.

Share:
Flickr Discloses Potential Data Exposure via Third-Party Email Service Provider
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

4 events from the most recent confirmed update back to the earliest known activity.

4 EVENTS
Feb 6, 20265mo ago

Flickr announces broader third-party security review and user warnings

Following the disclosure, Flickr said it was strengthening architecture, monitoring, and oversight around third-party providers, and warned users to watch for phishing, review account settings, and change reused passwords on other services.

Flickr notifies users and data protection authorities

Flickr began disclosing the incident to customers and notified relevant data protection authorities, stating that potentially exposed data included names, email addresses, usernames, account types, IP or location-related data, and activity logs, while passwords and payment information were not affected.

Feb 5, 20265mo ago

Flickr contains exposure by disabling affected vendor access

Within hours of learning of the issue on 2026-02-05, Flickr shut down access to the affected vendor system, removed links to the vulnerable endpoint, notified the provider, and requested an investigation.

Flickr alerted to third-party email provider vulnerability

On 2026-02-05, Flickr said it was notified of a security vulnerability in a system operated by an external email service provider that may have enabled unauthorized access to some member data.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

9 LINKEDOpen in app
Affected products
3 linked
TelegramWhatsappDiscord
Organizations
6 linked
FlickrSmugMugHackReadSubstackThe RegisterSecurity Affairs
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.

Flickr Discloses Potential Data Exposure via Third-Party Email Service Provider | Mallory