Badoo data breach (2013)
A dataset attributed to the dating and social network Badoo exposed roughly 112 million unique email addresses along with names, birthdates and MD5 password hashes; the data surfaced among traders in 2016 and remains formally unverified.
- Victim
- Badoo
- records
- 112.0M
- users
- 112.0M
A large dataset attributed to the London-based dating and social-discovery network Badoo surfaced among data traders in mid-2016, containing roughly 112 million unique email addresses together with names, birthdates and MD5 password hashes. The data is believed to have been obtained several years earlier, around 2013, but its authenticity has never been definitively confirmed β Have I Been Pwned classifies the breach as "unverified."
What happened
The breach was not announced by Badoo or discovered through a public intrusion at the time. Instead, in June 2016, a dataset purporting to come from Badoo began circulating amongst traders, alongside a series of other large historical breaches that emerged that year. Analysts dated the records to roughly 2013, suggesting the data β if genuine β had been quietly held or traded privately for years before reaching wider markets.
What was exposed
According to indexing by Have I Been Pwned, the dataset contained:
- 112,005,531 unique email addresses
- Names and usernames
- Dates of birth and gender
- Passwords stored as MD5 hashes
Because MD5 is a fast, cryptographically weak hashing algorithm, any passwords in the set would have been highly vulnerable to large-scale cracking, particularly for weaker or common passwords.
Verification and uncertainty
A defining feature of this incident is its unverified status. While numerous indicators pointed to Badoo as the origin of the data, researchers were unable to emphatically prove the legitimacy of the records. Have I Been Pwned therefore loaded it as both unverified (authenticity not conclusively established) and sensitive (not publicly searchable, given the dating-site context, with exposure viewable only after email verification).
Why it matters
The Badoo case illustrates two recurring features of the 2016 "historical mega breach" wave. First, the long latency between compromise and disclosure: data apparently taken around 2013 only became visible to defenders and affected users years later. Second, the attribution and verification problem: a dataset can carry enough internal markers to be plausibly linked to a service while still falling short of confirmable proof. For users, the practical advice was unchanged β assume the email/password pairs may be real, change reused passwords, and treat the dating-site context as sensitive given the risk of targeted phishing or extortion.
Timeline
The breach is believed to have originated around mid-2013, the approximate date the exposed Badoo records date from.
A dataset attributed to Badoo begins circulating among data traders on underground markets.
Have I Been Pwned loads 112,005,531 unique Badoo records, flagging the breach as both 'unverified' and 'sensitive'.
Badoo states it has no evidence of a current compromise; the legitimacy of the dataset cannot be conclusively proven.
Sources
- haveibeenpwned.comhttps://haveibeenpwned.com/Breach/Badoo
- dehashed.comhttps://dehashed.com/insights/badoo-data-breach-2013-june
- twingate.comhttps://www.twingate.com/blog/tips/badoo-data-breach
- csidb.nethttps://www.csidb.net/csidb/incidents/c67f2122-efbc-49b9-937c-7cb52f152297/