Cybercrooks trawl Fishbrain to net password hashes
Fishbrain, an app used by more than 20 million anglers, has disclosed a data breach after cybercriminals stole password hashes and salts belonging to its users, alongside other personal details. The Swedish company reported the incident to the California Attorney General's Office this week, revealing the intrusion occurred on 19 August. While passwords were not stored in plaintext, Fishbrain admitted that some of the compromised hashes may be vulnerable to cracking, meaning attackers could potentially recover the original passwords using their own computing power.
Alongside password hashes and salts, the stolen data included names, dates of birth, email addresses, phone numbers, usernames and country information. Fishbrain did not disclose how many users were affected or which hashing algorithm it used, and it has not commented further when approached by The Register. In response, the company patched the vulnerability, reset all user passwords, restricted access to the affected systems, and is conducting a broader security review. It has urged users to change any other accounts sharing the same password, and to remain alert to potential phishing attempts using the stolen personal data.
- Fishbrain, used by 20m+ anglers, suffered a breach on 19 August
- Stolen data includes password hashes, salts and personal details
- Company reset all passwords and warns of possible phishing follow-up