Breach report
Consumer TechUnder Armour (MyFitnessPal)
Under Armour says data breach affected about 150 million MyFitnessPal accounts
Under Armour disclosed in March 2018 that an unauthorized party had taken usernames, email addresses and hashed passwords for about 150 million users of its MyFitnessPal diet and exercise app.
Reported by CNBC
Records exposed
150M
About 150 million accounts
Scale vs. largest on file
- When
- 2018
- How they got in
- Unauthorized access to app data (method not disclosed)
- Sector
- Consumer Tech
On March 29, 2018, Under Armour announced that data associated with about 150 million MyFitnessPal accounts had been acquired by an unauthorized party. The popular food and exercise tracking app, which the sportswear company bought in 2015 as part of a push into connected fitness, had been accessed in late February. Under Armour said it learned of the incident on March 25 and began notifying users within four days.
The compromised information included usernames, email addresses and hashed passwords. Under Armour said most passwords were protected with bcrypt, a strong hashing function, while the rest used SHA-1, an older and weaker method. The company said payment card data was collected and processed separately and was not affected, and that the app did not collect government identifiers such as Social Security or driver's license numbers.
Under Armour did not explain how the attackers gained access. It said it was working with outside security firms and law enforcement, required users to change passwords, and urged them to watch for phishing messages. The company's shares fell nearly 4 percent in after-hours trading on the news before recovering some ground. At the time it was one of the largest breaches ever disclosed, and it drew praise from some security experts for the speed of notification compared with many peers.
The data did not stay quiet. In February 2019, roughly 151 million MyFitnessPal records appeared among the 620 million accounts offered for sale on a dark web marketplace by the hacker known as GnosticPlayers, alongside data from Dubsmash, MyHeritage and other sites. Under Armour later sold MyFitnessPal to private equity firm Francisco Partners in 2020 as it scaled back its connected fitness ambitions.
The breach showed that fitness and wellness apps hold data that attackers value even without payment details, since email and password pairs can be used to break into other accounts. It also illustrated the risk of mixed password-hashing schemes: the SHA-1 portion of the data was far easier to crack than the bcrypt portion. For consumers, it was a reminder to use distinct passwords for lifestyle apps, and for companies it demonstrated that rapid disclosure can limit reputational damage.