Fishing App Fishbrain Hooked by Data Breach, Password Hashes Exposed
Fishbrain, the fishing app that claims over 20 million users worldwide, has disclosed a data breach to the California Attorney General's Office after criminals made off with a haul of user data in August.
The stolen goods include names, dates of birth, email addresses, phone numbers, usernames, country data, and critically, password hashes along with their corresponding salts. That last detail is the uncomfortable part.
Passwords weren't stored in plaintext, which is the bare minimum anyone should expect. But Fishbrain has acknowledged that the compromised hashes "may be susceptible to being decoded" for some users. Translation: if your password was weak, or the hashing algorithm was anything less than robust, someone with enough hardware could work backwards and recover your actual credentials.
Fishbrain hasn't said which hashing algorithm it used. That omission matters enormously. MD5 or SHA-1 hashes can be cracked at billions of guesses per second on consumer GPUs. bcrypt or Argon2 are a different story. We don't know which camp Fishbrain falls into, and apparently the company would rather not say.
The breach itself occurred on 19 August. How many of those 20 million accounts were actually affected remains unclear. Fishbrain isn't talking numbers.
For now, Fishbrain has reset all user passwords, patched whatever vulnerability let the attackers in, and claims to have restricted access to the affected systems. A broader security review is apparently underway.
The standard advice applies. If you reused your Fishbrain password anywhere else, change it everywhere, now. Use a password manager. Stop reusing passwords. This kind of breach is exactly why credential stuffing attacks work so well.
The Register has contacted Fishbrain for further comment. We won't hold our breath.