
CouchSurfing of, an online service that allows users to find free accommodations, is investigating a data breachafter hackers 17 million users on Telegram channels and hacking forums.
According to the data broker, the guy selling the breached data, the information is currently being sold for $700.
The data broker did not provide details about the identity of the hacker, but said the CouchSurfing data first appeared in private Telegram channels last week. The advertisement said the data was stolen from CouchSurfing servers earlier this month.
No passwords were leaked
The user details that appear to have been leaked include: user IDs, real names, email , and CouchSurfing account settings.
The users' passwords have not been exposed. However, we do not know if the hackers stole the passwords and simply chose not to share them.
A CouchSurfing spokesperson said the company is already working with a security firm to investigate the breach, and has also notified law enforcement agencies
As we said above, the data was initially released in private Telegram channels but this week it also started appearing on hacking forums, including the infamous RAID Forum, where stolen databases are sold.

CouchSurfing is now considered one of the 11,000 most popular sites on the Internet. The service, founded in 2004, has 12 million registered users on its website. There used to be more users, but the company has been purging inactive users. This probably explains the fact that hackers are selling the data of 17 million people (the hackers also found the data of inactive users).
The impact of the CouchSurfing breach is smaller than other security incidents at other companies, as no passwords were exposed .This means that CouchSurfing data cannot be used as part of credential stuffing botnets that take credentials and try to log into a user's accounts on other online services.
However, CouchSurfing users' emails can be used for phishing distribution campaigns malware.
The data broker said that the CouchSurfing data may have come from backup files, as most companies create backups of their user databases and usually do not include passwords.
