As cited
Copy frozen at (site build).
breaches incidents
Cybercrooks trawl Fishbrain to net password hashes
Fishbrain, a fishing app with over 20 million users, disclosed a breach occurring on August 19, 2026, in which attackers obtained user password hashes, salts, names, dates of birth, email addresses, phone numbers, usernames, and country information. The company determined that some of the compromised password hashes may be susceptible to decoding, prompting forced password resets for all users. Fishbrain has patched the vulnerability, restricted access to the affected environment, and strengthened security controls while continuing its investigation.
Why it matters: Fishbrain users face credential cracking and phishing attacks if their passwords are weak or reused across accounts; practitioners should advise users to apply unique, strong passwords everywhere and monitor for follow-on social engineering attempts targeting the disclosed personal data.
- Source published
- First seen by Cybersecurity Tracker