Hackers steal password hashes and salts from fishing app Fishbrain
Cybercriminals accessed a database of Fishbrain users, extracting password hashes, salts and personal details after a breach reported to California authorities.
Fishbrain AB, which claims over 20 million anglers use its app, confirmed that an intrusion on August 19 allowed unknown hackers to download extensive user records. The stolen data set contains personal identifiers such as names, dates of birth, email addresses, phone numbers, usernames, country details, as well as password hashes and associated salts. While passwords were not stored in plain text, the company warned that some hashes might be crackable, contingent on the strength of the original passwords and the undisclosed hashing algorithm.
After detecting the breach, Fishbrain repaired the exploited vulnerability, restricted access to the affected environment, and initiated a comprehensive security review. All users will be required to set new passwords at their next login, and the firm urged anyone reusing the same credentials elsewhere to change them promptly.
Why it matters
Compromised password data from a widely used app could lead to credential theft across multiple online services.
In this story
