Skip to main content
  1. Home
  2. Computing
  3. Web
  4. News

Here’s a list of sites and services affected by Cloudbleed, and what to do next

Add as a preferred source on Google

Last week, we found out about Cloudbleed, a major leak of user data affecting sites and services that use infrastructure provided by Cloudflare. It’s still too early to determine the scale of the problem — but it’s an ideal time to respond if you’re looking to avoid the fallout.

Cloudbleed refers to a memory leak that caused user data from apps and websites that use Cloudflare’s services to be splashed across the internet, and is being compared to the Heartbleed bug that reared its head in 2014. Unfortunately, it’s thought that some of the data leaked as a result of Cloudbleed may have been cached by search engines, meaning that malicious entities could have intercepted it, according to a report from Gizmodo.

Recommended Videos

Cloudflare has such an enormous list of clients that it’s difficult to list every single site and service that could be affected — although an effort to do just that is in progress on GitHub. Here’s a list of some of more commonly used domains that could have had user data leaked (although there’s no confirmation that they’ve been compromised as of yet):

  • uber.com
  • yelp.com
  • medium.com
  • 4chan.com
  • bitcoin.de
  • fitbit.com
  • authy.com
  • tfl.gov.uk
  • okcupid.com
  • discordapp.com
  • feedly.com
  • thepiratebay.org
  • pastebin.com
  • change.org
  • puu.sh

The above is by no means a definitive list, as millions of domains could potentially be at risk. However, it should demonstrate the variety of services that could be affected.

To check whether any sites or apps you use are at risk, you can scour the full list on GitHub, or use the Does it use Cloudflare? web tool. However, most internet users are likely to hold an account on at least one affected site, so password refreshes are recommended for all.

Changing out every password you are currently using may seem extreme, but the stakes are high. If your user data has been leaked, and you use the same password for multiple sites, it might be possible for a stranger to gain access to all kinds of services on your behalf.

As such, it’s well worth doing a sweep now, and changing up your passwords to ensure that you’re kept safe. The inconvenience of spending a hour or two completing the task is a small price to pay for peace of mind.

This might also be a good time to improve your online security across the board. If you’re not already using a password manager and two-factor authentication to keep your accounts safe, there’s no better time to implement these services.

Above all else, vigilance is key. This is an evolving situation, since the problem was only made public a matter of days ago, and there are so many domains that could be affected. Keep a close eye on important accounts, and if you notice anything suspicious, make sure to follow up.

Brad Jones
Brad is an English-born writer currently splitting his time between Edinburgh and Pennsylvania. You can find him on Twitter…
Layr is a new macOS clipboard manager that replaces hotkeys with trackpad gestures
This new Mac app opens clipboard history with a four-finger tap instead of a keyboard shortcut
Cursor open on Mac

macOS users already have several clipboard manager options, including Paste and Maccy. Most of them work well, but they are usually built around keyboard shortcuts. That is useful for keyboard-heavy users, but it can feel out of place for users who rely on the trackpad for most of their work.

Layr, a new clipboard manager from the developer behind Declutr, takes a different approach. Rather than assigning a keyboard shortcut to open the clipboard history, the app lets users bring up a clipboard overlay with a four-finger tap on the trackpad.

Read more
YouTube’s AI content labels are getting a much-needed makeover
No more hunting through descriptions. YouTube's AI labels are finally moving front and center.
YouTube ai declaration longform video

This year’s Google I/O marked the transition of Google from a search company to a fully AI-focused company. The company launched several AI tools, but the one that matters the most for YouTubers is Google Omni, built for video generation and editing. 

While tools like Omni lower the barrier for creators, which is a good thing, it also results in the platform being inundated with low-effort AI content. The company understands that this will annoy a large percentage of its users, so it has been asking creators to disclose AI-generated content since 2024. 

Read more
AI models have a religion favoritism problem, and new research exposes it
AI models are subtly steering users toward certain religions, and most people have no idea it's happening.
Artificial Intelligence

A new research consortium has found something worth paying attention to: when you ask AI about grief, love, loss, or moral decisions, it almost never brings religion into the conversation.

The Consortium for Evaluation of Faith and Ethics in AI (CEFE-AI), a collaboration among researchers at Brigham Young University, Baylor University, the University of Notre Dame, and Yeshiva University, published its findings this week at the Summit on AI Ethics in Athens, Greece.

Read more