Breach report
Consumer TechDubsmash, MyHeritage, ShareThis and 13 other sites
620 million accounts stolen from 16 hacked websites now for sale on dark web, seller boasts
A hacker listed roughly 620 million accounts stolen from 16 websites, led by Dubsmash's 162 million users, for sale on a dark web marketplace in February 2019, exposing breaches several companies had not known about.
Reported by The Register
Records exposed
620M
About 620 million accounts across 16 sites
Scale vs. largest on file
- When
- 2019 (breaches dating mostly to 2018)
- How they got in
- Multiple website intrusions; data sold on dark web marketplace
- Sector
- Consumer Tech
In February 2019, a seller on the Dream Market dark web marketplace began offering account databases stolen from 16 websites, totaling roughly 620 million records, for less than $20,000 in bitcoin. The Register reviewed samples and reported the listings, which included several companies that had not previously disclosed any breach. The seller, later identified by the handle GnosticPlayers, said the data had mostly been taken in 2018.
The largest set came from Dubsmash, the lip-sync video app, with about 162 million accounts. Others included MyFitnessPal at about 151 million, genealogy service MyHeritage at 92 million, ShareThis at 41 million, fashion retailer HauteLook at 28 million, video maker Animoto at 25 million, and photo platforms EyeEm, Fotolog and 500px. Smaller sets came from Whitepages, 8fit, Armor Games, Bookmate, Coffee Meets Bagel, Artsy and DataCamp. The data varied by site but generally included email addresses, usernames and hashed passwords, and in some cases names, locations, dates of birth, IP addresses and profile details.
The listings forced a wave of confirmations. Several companies, including 500px, Artsy and Dubsmash, said after the report that they were investigating or that they had found evidence of intrusions, and some reset user passwords. MyFitnessPal and MyHeritage had already disclosed their breaches in 2018. The seller told reporters that the attackers had exploited vulnerabilities in web applications to gain access, but the precise methods for each site were never fully documented.
Within weeks, GnosticPlayers posted additional batches from dozens more sites, pushing the total well past 850 million accounts. The same actor would later claim breaches at Canva and Zynga. The listing was pulled from Dream Market shortly after it attracted attention, but copies circulated among criminals and were added to breach-notification services.
The episode illustrated how mid-sized consumer apps can be compromised for months without noticing, and how a single broker can aggregate stolen databases and resell them cheaply. It also showed the downstream harm of password reuse, since combined email and password lists from many sites fuel credential-stuffing attacks on banks, email providers and retailers. For companies, the lesson was that monitoring for their own data on underground markets can be the first sign of a breach.