ZeroHour
The Register · Securitypublished ()ingested Connor Jones

Cybercrooks trawl Fishbrain to net password hashes

mediumData breachimportance 48
AI summary · glm-5.3-flash

Fishing app Fishbrain disclosed a breach exposing names, emails, and password hashes with salts for users of its 20-million-member platform.

Fishbrain AB disclosed to the California Attorney General's Office that attackers accessed user data on August 19, 2026, taking names, dates of birth, email addresses, phone numbers, usernames, country information, password hashes, and salts. The company said passwords were not stored in plaintext but some hashes may be susceptible to cracking; it patched the exploited vulnerability, reset all user passwords, and restricted access to the affected environment. Fishbrain, which claims more than 20 million users, did not disclose how many accounts were affected or which hashing algorithm was used.

  • Intrusion occurred August 19, 2026; disclosed via the California AG's office
  • Password hashes and salts stolen, enabling offline cracking attempts
  • All user passwords reset and access to the affected environment restricted
  • Breach scale and hashing algorithm details withheld
Full article342 words · extracted from theregister.com · click to collapse

cyber-crime

Armed with password hashes and salts, attackers could already be kraken those creds

Cybercriminals have reeled in password hashes and corresponding salts belonging to users of popular fishing app Fishbrain, opening the door to cracking attempts.

Fishbrain AB, which says its eponymous app serves more than 20 million anglers, disclosed the August 19 breach to the California Attorney General's Office this week.

The unknown perpetrators helped themselves to a trawl of user data, including names, dates of birth, email addresses, phone numbers, Fishbrain usernames, country information, password hashes, and salts.

REG AD

"Fishbrain passwords were not stored in plaintext; however, Fishbrain has determined that the compromised password hashes for some users may be susceptible to being decoded," the company said in its disclosure [PDF].

REG AD

It added: "If you use your Fishbrain password for any other online accounts, you should promptly update those passwords and any associated security questions or answers.

"You should also take other appropriate steps to protect any online accounts that use the same username or email address and password combination. We recommend using a strong, unique password for each of your accounts."

With the hashes and salts in hand, attackers can make password guesses using their own hardware until they potentially recover the original credentials.

Whether those attempts succeed depends on the strength of each password and the hashing algorithm Fishbrain used, which the company did not disclose.

Fishbrain did not comment on the scale of the breach or how many of its claimed 20 million-plus users were affected.

The Register asked Fishbrain for more information.

After discovering the intrusion and conducting an initial forensic investigation, Fishbrain patched the vulnerability and reset every user's password. Customers must create a new one the next time they log in.

Fishbrain also said it "restricted access to the affected environment," strengthened its security controls, and initiated "a broader review of our data security measures" while the investigation continues.

REG AD

Fisherfolk should also keep an eye out for phisherfolk using the stolen personal data to bait follow-on attacks. ®

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.theregister.com/cyber-crime/2026/09/03/cybercrooks-trawl-fishbrain-to-net-password-hashes/5294158