Fishbrain App Breach Exposes Password Hashes and User Data for Millions of Anglers
Cybercriminals have stolen password hashes and corresponding salts from Fishbrain, a popular fishing app with over 20 million users, potentially enabling credential-cracking attacks. The breach, disclosed to the California Attorney General’s Office on August 19, also exposed names, dates of birth, email addresses, phone numbers, usernames, and country information.
While Fishbrain did not store passwords in plaintext, the company acknowledged that some compromised hashes could be decoded, depending on password strength and the undisclosed hashing algorithm used. The exact number of affected users remains unclear, as Fishbrain has not provided details on the breach’s scale.
After detecting the intrusion, Fishbrain patched the vulnerability, reset all user passwords, and required users to create new credentials upon next login. The company also restricted access to the affected environment, enhanced security controls, and launched a broader review of its data protection measures.
With stolen personal data in hand, attackers may leverage the information for phishing or follow-on attacks, posing additional risks to users. The investigation remains ongoing.
Fishbrain cybersecurity rating report: https://www.rankiteo.com/company/fishbrain-ab
"id": "FIS1788467534",
"linkid": "fishbrain-ab",
"type": "Breach",
"date": "8/2026",
"severity": "85",
"impact": "4",
"explanation": "Attack with significant impact with customers data leaks"
{'affected_entities': [{'industry': 'Social Networking/Outdoor Activities',
'name': 'Fishbrain',
'size': '20 million users',
'type': 'Mobile App'}],
'customer_advisories': 'Users required to reset passwords and create new '
'credentials',
'data_breach': {'personally_identifiable_information': 'Names, dates of '
'birth, email '
'addresses, phone '
'numbers, usernames, '
'country information',
'sensitivity_of_data': 'High',
'type_of_data_compromised': 'Password hashes, salts, '
'personally identifiable '
'information'},
'date_publicly_disclosed': '2024-08-19',
'description': 'Cybercriminals have stolen password hashes and corresponding '
'salts from Fishbrain, a popular fishing app with over 20 '
'million users, potentially enabling credential-cracking '
'attacks. The breach also exposed names, dates of birth, email '
'addresses, phone numbers, usernames, and country information.',
'impact': {'data_compromised': 'Password hashes, salts, names, dates of '
'birth, email addresses, phone numbers, '
'usernames, country information',
'identity_theft_risk': 'High'},
'investigation_status': 'Ongoing',
'post_incident_analysis': {'corrective_actions': 'Broader review of data '
'protection measures'},
'references': [{'source': 'California Attorney General’s Office'}],
'regulatory_compliance': {'regulatory_notifications': 'Disclosed to the '
'California Attorney '
'General’s Office'},
'response': {'containment_measures': 'Restricted access to the affected '
'environment',
'enhanced_monitoring': 'Enhanced security controls',
'remediation_measures': 'Patched the vulnerability, reset all '
'user passwords, required users to '
'create new credentials upon next login'},
'threat_actor': 'Cybercriminals',
'title': 'Fishbrain App Breach Exposes Password Hashes and User Data for '
'Millions of Anglers',
'type': 'Data Breach'}