Skip to content
Data breachResolved

Dubsmash data breach (2018)

The video-messaging app Dubsmash was breached in December 2018, exposing roughly 162 million accounts with email addresses, usernames and PBKDF2 password hashes that later surfaced for sale on the Dream Market dark-web bazaar via the broker GnosticPlayers.

Victim
Dubsmash
records
161.7M
users
161.7M

In December 2018, the popular video-messaging and lip-sync app Dubsmash suffered a data breach that compromised roughly 162 million user accounts. The incident only became public in February 2019, when the stolen records appeared for sale on the Dream Market dark-web marketplace as part of a sprawling collection peddled by the broker known as GnosticPlayers.

What happened

Dubsmash, founded in Germany and later headquartered in New York, never publicly detailed the intrusion vector. What is known comes from the data itself and from the marketplace listing. The attacker exfiltrated the user database at some point around December 2018 and held it until early 2019, when GnosticPlayers bundled it with data stolen from a long list of other services.

The Dubsmash records were part of the second round of GnosticPlayers' campaign โ€” a combined dump of roughly 620 million accounts spanning sixteen companies, offered for about $20,000 in bitcoin. Dubsmash, at ~162 million records, was the single largest dataset in that batch.

Data exposed

The breach corpus contained:

  • Email addresses (161,749,950 unique addresses loaded into Have I Been Pwned)
  • Usernames
  • Names and, in some records, geographic location and spoken languages
  • Phone numbers for a subset of users
  • Passwords stored as PBKDF2 hashes

The use of PBKDF2 โ€” a deliberately slow, salted key-derivation function โ€” meant passwords were considerably better protected than the plaintext or unsalted-MD5 stores seen in older mega-breaches. Still, weak passwords remained vulnerable to offline cracking.

Impact and response

Dubsmash did not issue a prominent public breach notice, drawing criticism from security commentators. Users learned of their exposure primarily through Have I Been Pwned notifications. With email-and-password pairs in circulation, the principal risk was credential stuffing against other services where users had reused the same password.

Why it matters

The Dubsmash breach is best understood as one node in the GnosticPlayers phenomenon: a broker who, across several 2019 rounds, listed close to a billion stolen accounts from dozens of companies โ€” including Houzz, MyFitnessPal, MyHeritage, ShareThis and CoffeeMeetsBagel. It illustrated how a single actor could industrialise the resale of breach data, and how consumer apps that collect large user bases become high-value targets regardless of how "trivial" the service appears. The episode also reinforced the value of strong password hashing: PBKDF2 limited the damage relative to peers in the same dumps.

Timeline

  1. Attackers exfiltrate the Dubsmash user database containing roughly 162 million records.

  2. The data appears in a 620-million-account collection listed for sale on the Dream Market by the broker GnosticPlayers.

  3. Have I Been Pwned loads 161,749,950 Dubsmash accounts after verification.

  4. Reporting confirms Dubsmash among the batch of companies whose stolen data GnosticPlayers monetised across multiple rounds.

Sources

  1. haveibeenpwned.comhttps://haveibeenpwned.com/Breach/Dubsmash
  2. bleepingcomputer.comhttps://www.bleepingcomputer.com/news/security/collection-of-127-million-stolen-accounts-up-for-sale-on-the-dark-web/
  3. en.wikipedia.orghttps://en.wikipedia.org/wiki/GnosticPlayers
  4. theregister.comhttps://www.theregister.com/2019/03/04/armor_games_breach_disclosure/

Related incidents

Data breachResolved

HauteLook data breach (2018)

In mid-2018, the fashion shopping site HauteLook was among a raft of sites that were breached and their data then sold in early-2019. The data included over 28 million unique email addresses alongside names, genders, dates of birth and passwords stored as bcrypt hashes.

Victim
HauteLook
Records
28.5M