As of time (18 Apr 2021 2:00 PM UTC) of writing this post, we have
positively identified the database leak in the wild, as we had feared would happen. This means that your
username, email, IP address and
securely hashed passwords are now potentially public knowledge. If you have not done so yet, we
strongly advise that you
change your credentials on any site that you may have shared with MangaDex. We are currently working with HIBP (
https://haveibeenpwned.com/) to get the affected accounts added and notified, and plan to find a way to properly notify everyone affected via email.
As of now, the leak is not public and is instead being shared privately among certain groups of people who have ill intentions against MangaDex and have chosen to be complicit in the breach by keeping quiet about it, likely for unethical reasons. We do not know how many people have their hands on the data, or how long they have had it, but we expect the responsible parties to escalate the situation soon after by releasing the data publicly in some form.
We apologise for allowing this incident to happen, and we promise to do better in MangaDex v5.
EDIT #1: Your passwords are still securely hashed with bcrypt, no plaintext/visible passwords were found in the leak as of this time.
EDIT #2: Your last accessed IP may also be exposed in the database leak.
EDIT #3: For better explanation on how your passwords are stored, here's a handy dandy video that just about explains the basics: