On December 12, 2023, InflateVids appeared in a breach notification on Have I Been Pwned, confirming that the inflatable and balloon fetish video website had exposed records belonging to 13,000 users. The incident, which occurred earlier that year, placed email addresses, usernames, IP addresses, genders, and SHA-1 password hashes into the open. Anyone who created an account on the platform now faces the concrete risk that this information is circulating among data traders and extortion groups.
Named in this incident?
You can’t unleak data. You can take away what it’s worth.
A leaked record is where it starts, not where it ends. What turns it into your front door is the look-up sites publishing your address beside your name — and those are what an AI reads when somebody asks about you. The free scan shows you both. We write to 580 companies.
See what is exposed about you — free scan →Watch InflateVids
Get alerted the next time InflateVids files a breach with any US regulator — the filing, dated and sourced. A free single-company slice of Signals; no account needed.
We’ll email you only about InflateVids’s future breach filings and how to watch a whole vendor list — not general marketing. Unsubscribe any time.
Watching your whole vendor list (50 to 500 companies, by tier) is GalaxyWarden Signals.
Confirmed Breach Details
The primary disclosure on Have I Been Pwned states that the breach exposed 13K unique email addresses, usernames, IP addresses, genders, and SHA-1 hashed passwords. The listing does not specify the exact intrusion method, whether the data was stolen through a ransomware attack, a simple database dump, or another vector. It also does not indicate whether the passwords were salted, leaving open the possibility that many of the SHA-1 hashes could be cracked with modest computing resources. No ransom demand or extortion letter is mentioned in the public record.
Why This Matters for You and Your Family
If you or anyone in your household used InflateVids, your email address and password hash are now available to anyone willing to search underground forums. An exposed IP address can narrow down your geographic location, while gender and username data help attackers build a profile that makes phishing or social-engineering attempts more convincing. Because many people reuse the same password across sites, a single breach like this can quietly open the door to email accounts, banking logins, or social-media profiles used by you or your children. The breach is now more than a year old, which means opportunistic criminals have had time to test and sell the data.
Doxxing and Identity-Chain Risks
Username and email combinations from niche communities frequently serve as the first link in doxxing chains. Once an attacker ties your InflateVids username to an email, they can query the same username across gaming platforms, forums, and social apps. An exposed IP address further tightens the net, sometimes revealing your internet service provider and general area. These threads can lead to full identity exposure, including home address, phone numbers, and family member names. Credential leaks of this type regularly cascade into account takeovers on Steam, Discord, Roblox, and other services used by children and teenagers. The longer the data sits in the wild, the more connections an attacker can map.