Thingiverse, the site for community sharing of 3D printing templates and other digital design files, has been the victim of an unfortunate data leak, with 36GB of unique email addresses and ‘other personally identifiable information’ appearing on a popular hacking forum. The leak was confirmed by Have I Been Pwned creator Troy Hunt in a statement to Information Security Media Group .

The leaked backup file appears to contain a MySQL database with more than 255 million lines of data, according to Hunt. Within, is “data on the 3D models that are publicly accessible, but there are also email and IP addresses, usernames, physical addresses and full names". Date stamps appear to go back at least a decade.
While there's no sign that plain text passwords have been leaked, Have I Been Pwned tweeted about the presence of “unsalted SHA-1 or bcrypt password hashes” in the data. Salt is random data added to the hashing process (a one-way transformation) to increase complexity. While hashed passwords are still unreadable without considerable effort, they’re easier to decrypt without the presence of salt.
The breach was first discovered on October 1st by Twitter user pompompurin , as a result of a "misconfigured S3 bucket" from Thingiverse's backup data.
Thingiverse's owner, MakerBot, has been made aware of the incident but, at the time of writing, is yet to issue a statement. Now would be a really good time to change your Thingiverse password, along with the passwords for any other sites you may have inadvertently reused the same credentials for.
