Flickr notified users of a potential data breach after discovering a vulnerability in a third-party email service provider system that may have enabled unauthorized access to some member information. Flickr said it was alerted to the flaw on February 5, 2026 and disabled access to the affected system within hours. The company did not name the provider or disclose how many users were impacted, but stated that exposed data may include real names/usernames, email addresses, account types, IP addresses, general location data, and account activity.
Flickr stated that passwords and payment card data were not compromised, reducing immediate risk of direct account takeover but increasing risk of phishing and targeted social engineering using the exposed profile and activity details. Users were advised to review account settings for unexpected changes and to be cautious of messages referencing their Flickr accounts, with Flickr emphasizing it will not request passwords via email. Separately, Substack reported a different breach involving unauthorized access to limited user data and dark web leak claims; it is not connected to the Flickr incident.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
4 events from the most recent confirmed update back to the earliest known activity.
Following the disclosure, Flickr said it was strengthening architecture, monitoring, and oversight around third-party providers, and warned users to watch for phishing, review account settings, and change reused passwords on other services.
Flickr began disclosing the incident to customers and notified relevant data protection authorities, stating that potentially exposed data included names, email addresses, usernames, account types, IP or location-related data, and activity logs, while passwords and payment information were not affected.
Within hours of learning of the issue on 2026-02-05, Flickr shut down access to the affected vendor system, removed links to the vulnerable endpoint, notified the provider, and requested an investigation.
On 2026-02-05, Flickr said it was notified of a security vulnerability in a system operated by an external email service provider that may have enabled unauthorized access to some member data.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
8 references tracked. Mallory keeps watching after this page renders.
scworld.com
Open sourcetechrepublic.com
Open sourcesecurityaffairs.com
Open sourcethecyberthrone.in
Open sourcego.theregister.com
Open sourcehackread.com
Open sourcecybersecuritynews.com
Open sourcebleepingcomputer.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.