← All datasets

picsart.com

Mar 17, 2014

100,000
Records
1
Files
May 30, 2026
Added

A breach of PicsArt, the photo editing and social platform, containing user account data from around March 2014. Records include internal MongoDB IDs, usernames, names, profile photo URLs (hosted on cdn.picsart.com and cdn23.picsart.com), email addresses (many null), OAuth tokens for Twitter and Facebook (including access tokens and secrets), provider type (twitter/facebook/site), account creation and update timestamps, and various account flags. The presence of OAuth tokens makes this particularly sensitive.

Data found in this dataset

EmailUsernameskipfullName

Search this dataset

Scoped to this dataset. Fill any combination — results match if any field hits.

Source files

Expand any file to inspect its column headers and the LLM's field-mapping reasoning, recorded during ingestion.

part1.json
25 columns100,000 rows

File structure

Format: NDJSON

Source columnMapped fieldConfidenceLLM assessment
dateskiphightimestamp string, metadata
twitterskiphighOAuth provider data structure (token/secret handled separately as sensitive but not mapped field)
topskiphighboolean flag, metadata
providerskiphighauthentication provider type (twitter/facebook/google/site)
permissionsskiphighinternal metadata array
originsskiphighinternal metadata array
idskiphighnumeric user ID
categoriesskiphighinternal metadata array
keyskiphighinternal UUID identifier
emailemailhighemail addresses with @ symbol or null values
is_searchableskiphighboolean flag, account setting
subscribeskiphighboolean flag, account setting
createdskiphightimestamp, CRM metadata
facebookskiphighOAuth provider data structure (token/secret handled separately as sensitive but not mapped field)
verifiedskiphighboolean flag, account status
photoskiphighprofile photo URLs, not PII
blacklistskiphighboolean flag, account status metadata
googleskiphighOAuth provider data structure (token/secret handled separately as sensitive but not mapped field)
email_confirmedskiphighboolean flag, email verification status
namefullNamehighcontains full names of users
username_changedskiphighboolean flag, metadata
commentskiphighempty/optional field, metadata
_idskiphighMongoDB internal ID
updatedskiphightimestamp, CRM metadata
usernameusernamehighPicsArt account usernames

Notes: PicsArt 2014 breach: MongoDB user account export. OAuth tokens (Twitter, Facebook, Google) present in nested provider objects are highly sensitive but not mapped to a PII field type—they represent authentication credentials. The 'name' field contains user display names which map to fullName. Email field frequently null for OAuth-linked accounts. All nested OAuth data (tokens, secrets, profile data) should be treated as compromised credentials.

picsart.com. Shadow Identity