In November 2025, the online coding practice platform CodeStepByStep exposed the personal details of 103,000 users after two separate data releases one month apart. The breach made names, usernames, and email addresses publicly available, affecting anyone who had created an account on the site to practice programming exercises.
Named in this incident?
You can’t unleak data. You can take away what it’s worth.
A leaked record is where it starts, not where it ends. What turns it into your front door is the look-up sites publishing your address beside your name — and those are what an AI reads when somebody asks about you. The free scan shows you both. We write to 582 companies.
See what is exposed about you — free scan →Not ready yet? Run a free breach check on this email
We’ll check it against 13.1B+ leaked records right now — no account needed. Continuous monitoring & alerts are part of Protection.
What's Publicly Reported from Reporting
Public reporting from Have I Been Pwned states the first batch of 17,000 records appeared in November 2025. A second, larger set followed in December 2025, bringing the total to 103,000 affected accounts. The exposed information consists solely of names, usernames, and email addresses. No passwords, financial data, or government identifiers were included in the published material. The platform has not issued a detailed public statement on how the breach occurred or exactly when the data was first taken.
Why This Matters for You and Your Family
Even a seemingly small breach like this one creates lasting risk. Email addresses and usernames are often the exact pieces of information attackers need to launch credential-stuffing attacks against your other accounts. If you or your children used the same email and username combination on CodeStepByStep that appears elsewhere, those details can be tested automatically across banking, school, shopping, and social platforms. For families, the exposure of a child’s username tied to a parent’s email can open the door to harassment or further data harvesting. The low severity label attached to the incident does not reduce the practical danger once the information sits on multiple leak sites and forums.
The Doxxing and Identity-Chain Implications
Names, usernames, and emails form the starting links in what security analysts call an identity chain. A single username can connect gaming accounts, forum profiles, social media handles, and sometimes home addresses through cross-referencing tools. Once attackers map these connections, they can escalate from simple spam to targeted doxxing, account takeovers, or extortion. Credential leaks of this nature frequently cascade into gaming account compromises, especially when children reuse usernames across coding sites and popular game platforms. The published data remains downloadable, meaning the exposure window stays open indefinitely unless you actively break those chains.