Skip to main content
Breach Signal

Breach report

Consumer Tech

Dubsmash, MyHeritage, ShareThis and 13 other sites

620 million accounts stolen from 16 hacked websites now for sale on dark web, seller boasts

A hacker listed roughly 620 million accounts stolen from 16 websites, led by Dubsmash's 162 million users, for sale on a dark web marketplace in February 2019, exposing breaches several companies had not known about.

Reported by The Register

Records exposed

620M

About 620 million accounts across 16 sites

Scale vs. largest on file

When
2019 (breaches dating mostly to 2018)
How they got in
Multiple website intrusions; data sold on dark web marketplace
Sector
Consumer Tech

In February 2019, a seller on the Dream Market dark web marketplace began offering account databases stolen from 16 websites, totaling roughly 620 million records, for less than $20,000 in bitcoin. The Register reviewed samples and reported the listings, which included several companies that had not previously disclosed any breach. The seller, later identified by the handle GnosticPlayers, said the data had mostly been taken in 2018.

The largest set came from Dubsmash, the lip-sync video app, with about 162 million accounts. Others included MyFitnessPal at about 151 million, genealogy service MyHeritage at 92 million, ShareThis at 41 million, fashion retailer HauteLook at 28 million, video maker Animoto at 25 million, and photo platforms EyeEm, Fotolog and 500px. Smaller sets came from Whitepages, 8fit, Armor Games, Bookmate, Coffee Meets Bagel, Artsy and DataCamp. The data varied by site but generally included email addresses, usernames and hashed passwords, and in some cases names, locations, dates of birth, IP addresses and profile details.

The listings forced a wave of confirmations. Several companies, including 500px, Artsy and Dubsmash, said after the report that they were investigating or that they had found evidence of intrusions, and some reset user passwords. MyFitnessPal and MyHeritage had already disclosed their breaches in 2018. The seller told reporters that the attackers had exploited vulnerabilities in web applications to gain access, but the precise methods for each site were never fully documented.

Within weeks, GnosticPlayers posted additional batches from dozens more sites, pushing the total well past 850 million accounts. The same actor would later claim breaches at Canva and Zynga. The listing was pulled from Dream Market shortly after it attracted attention, but copies circulated among criminals and were added to breach-notification services.

The episode illustrated how mid-sized consumer apps can be compromised for months without noticing, and how a single broker can aggregate stolen databases and resell them cheaply. It also showed the downstream harm of password reuse, since combined email and password lists from many sites fuel credential-stuffing attacks on banks, email providers and retailers. For companies, the lesson was that monitoring for their own data on underground markets can be the first sign of a breach.

More from the wire

More in Consumer Tech.

All 107 reports

Private AI for Life

Live your best life with Thinkspan: the all-in-one smart solution for organizing, securing, and accessing personal information. With Thinkspan, your life’s most important information stays protected and accessible.