# The Locally data breach, explained

Source: https://joinrepass.com/breach/locally/
Index: https://joinrepass.com/llms.txt

Data breach · 2022

Locally (locally.com) was breached on October 1, 2022, exposing 363 thousand accounts, passwords included. Here is exactly what leaked, what it means, and the order to fix things in.

362,619 accounts · 6 data classes · verified record

The numbers

## What the record shows

What leaked

## 6 kinds of data were exposed

The universal account key. Exposed addresses get targeted with credential-stuffing and phishing that name the breached site to look legitimate.

Not enough to charge on its own, but enough to make a fraudster on the phone sound like your bank.

The one that matters most. Even hashed passwords get cracked at scale, and every account where this password was reused is now reachable.

Enables SIM-swap attempts and smishing, and links this account to every other one that knows the number.

Where you live. Combined with a name it supports identity fraud and very convincing postal or doorstep scams.

What you bought. Fuel for invoice scams and refund phishing that reference real orders.

In this order

## What to do now

- Reset the Locally password firstUse the official forgot-password flow on locally.com directly, never a link from an email about the breach; breach news is prime phishing bait.

- Kill the reuse, which is the real damageEvery account sharing the exposed password is now one automated attempt from gone. This is the tedious part, and it is the part Repass automates: it finds the accounts and runs each site's official reset flow for you.

- Scan your email for the rest of your exposure[Run the free breach scan](https://joinrepass.com/) on the address you use most. Locally is one breach; the median active email address appears in several, and what to fix first depends on the full picture.

- Turn on two-factor authenticationA leaked password with a second factor in front of it is a locked door with a stolen key that no longer fits. Prefer an authenticator app over texted codes where the service offers the choice.

Questions

## Locally breach FAQ

The record covers 362,619 accounts. The quick way to check is a breach scan against your own email address, which searches this breach and hundreds of others at once. Repass runs one free on its homepage.

The Locally password itself, immediately. Then every other account where you used the same or a similar password, because that reuse is what attackers actually exploit.

Only if that password lived nowhere else. Credential-stuffing takes leaked email-and-password pairs and tries them on banks, mailboxes and stores at machine speed, so the reused copies matter more than the original. A reused password is a breach of every account that shares it.

The record lists partial credit card data among the exposed data. Watch the statements on any card used there, and treat calls or emails that quote card details as hostile until proven otherwise; quoting real fragments is how fraudsters borrow your bank's credibility.

From the public index maintained by Have I Been Pwned, which verifies breaches before listing them. This page renders the structured record: dates, account count and exposed data classes.

Run a breach scan on your email address. It returns every verified breach that lists the address, which is the honest starting point for deciding what to reset first. Repass then resets the passwords for you, one official flow at a time, and seals each new one in an encrypted vault.

More records

## Other major breaches

[All 851 breach records](https://joinrepass.com/breach/)

After the breach

## Every reused password, replaced for you.

3-day free trial · strong unique passwords · encrypted vault

Generated from the page itself. Structured data for this site: https://joinrepass.com/api/v1/services.json
