← BACK TO FEED
data breachpassword securitycredential theftcybercrimeFishbrain

Fishing App Fishbrain Hooked by Data Breach, Password Hashes Exposed

Fishing app Fishbrain, which claims over 20 million users, suffered a data breach on August 19 in which cybercriminals stole user data including names, email addresses, phone numbers, and password hashes with salts. Although passwords were not stored in plaintext, the stolen hashes could potentially be cracked depending on the strength of individual passwords and the hashing algorithm used. Fishbrain has since patched the vulnerability, reset all user passwords, and urged users to update their credentials on any other accounts where they used the same password.

Fishbrain, the fishing app that claims over 20 million users worldwide, has disclosed a data breach to the California Attorney General's Office after criminals made off with a haul of user data in August.

The stolen goods include names, dates of birth, email addresses, phone numbers, usernames, country data, and critically, password hashes along with their corresponding salts. That last detail is the uncomfortable part.

Passwords weren't stored in plaintext, which is the bare minimum anyone should expect. But Fishbrain has acknowledged that the compromised hashes "may be susceptible to being decoded" for some users. Translation: if your password was weak, or the hashing algorithm was anything less than robust, someone with enough hardware could work backwards and recover your actual credentials.

Fishbrain hasn't said which hashing algorithm it used. That omission matters enormously. MD5 or SHA-1 hashes can be cracked at billions of guesses per second on consumer GPUs. bcrypt or Argon2 are a different story. We don't know which camp Fishbrain falls into, and apparently the company would rather not say.

The breach itself occurred on 19 August. How many of those 20 million accounts were actually affected remains unclear. Fishbrain isn't talking numbers.

For now, Fishbrain has reset all user passwords, patched whatever vulnerability let the attackers in, and claims to have restricted access to the affected systems. A broader security review is apparently underway.

The standard advice applies. If you reused your Fishbrain password anywhere else, change it everywhere, now. Use a password manager. Stop reusing passwords. This kind of breach is exactly why credential stuffing attacks work so well.

The Register has contacted Fishbrain for further comment. We won't hold our breath.

READ NEXT
Threat Actor Claims Millions of Corporate Records Lifted from Azure TenantsShinyHunters Padded the Carhartt Breach With Millions of Fake Records£8K Phishing Kit Promises to Plant Fake Passkeys and Haunt Compromised Accounts Long After You've Changed Your Password