PicBackMan is a San Jose software service for automated photo and video backups to online services (www.linkedin.com). The reported April 17, 2026 leak contains 38,767 indexed records (leaksear.ch metadata).
The indexed data includes contact identifiers, password and hash fields, IP addresses, device telemetry, and subscription/payment metadata (leaksear.ch metadata).
What happened
The verified public reporting used for this article comes from breach-intelligence posts rather than a PicBackMan notice. Brinztech reported on April 16 and April 17, 2026 that a threat actor had published a PicBackMan database dump on a monitored hacker forum, and its expanded analysis described the dump as exposing user authentication architecture, hardware telemetry, and subscription metadata (www.brinztech.com, www.brinztech.com).
Those reports do not establish a root cause. Based on the public material reviewed, the exposure mechanism should be treated as unconfirmed rather than attributed to ransomware, scraping, misconfigured storage, or a named third-party compromise.
What data was exposed
leaksear.ch indexed 38,767 PicBackMan records with searchable fields for email, hashed password, IP address, name, password, and phone number (leaksear.ch metadata).
Additional stored fields include salts and extended hash values, login and access metadata, operating system and device details, PicBackMan client/version indicators, upload and deduplication counters, referral emails, account-status flags, and subscription or billing metadata. The payment-related metadata includes payment amount, company, payer email, customer and subscription identifiers, invoice and transaction identifiers, item names, payment source, subscriber type, and paid-user status (leaksear.ch metadata).
Why this matters
The combination of email addresses, names, phone numbers, IP addresses, and password-related fields creates practical account-takeover and credential-reuse risk, especially for users who reused a PicBackMan password elsewhere. Device, upload, and subscription context can also make phishing messages more convincing, including fake backup-failure, billing, or account-recovery lures. Readers who used PicBackMan should check whether their data appears in this leak before trusting unexpected backup, billing, or login messages.
Check your exposure
Vetted researchers and incident-response teams can request access or sign in if they already have access to check this dataset. Searchable pivots for this leak include email, hashed password, ip address, name, password, and phone.