Skip to content
Data breachResolved

MyFitnessPal data breach (2018)

In February 2018, Under Armour's MyFitnessPal app was breached, exposing about 144 million accounts with usernames, emails and passwords hashed using a mix of SHA-1 and bcrypt; the data later surfaced for sale via GnosticPlayers.

Victim
MyFitnessPal (Under Armour)
records
143.6M
users
143.6M

In February 2018, MyFitnessPal, the diet-and-exercise tracking app owned by apparel maker Under Armour, suffered a breach that exposed roughly 144 million accounts โ€” one of the largest single breaches of that year.

What happened

The intrusion occurred in February 2018, but Under Armour did not become aware of it until 25 March 2018, when it learned that an unauthorized party had acquired data tied to MyFitnessPal user accounts. The company disclosed the breach publicly four days later, on 29 March 2018, initially describing about 150 million accounts as affected. Under Armour's share price dropped on the announcement.

The stolen data later resurfaced in early 2019 as part of a massive tranche of 620 million records from 16 websites offered for sale by GnosticPlayers โ€” the same actor behind the Canva and Dubsmash breaches. Have I Been Pwned ultimately catalogued 143,606,147 unique accounts from the MyFitnessPal set.

What was exposed

The compromised records included usernames, email addresses, IP addresses, and passwords. Importantly, password protection was inconsistent: the majority were hashed with bcrypt, but a portion of older accounts used the weaker SHA-1 algorithm, leaving those credentials more vulnerable to cracking.

Under Armour emphasized what was not taken: the company does not collect government-issued identifiers such as Social Security or driver's license numbers, and payment card data was processed separately and was not affected.

Impact

  • Roughly 144 million account records were exposed and later traded on dark-web markets.
  • Under Armour required affected users to reset passwords and urged everyone to do so immediately, alongside in-app and email notifications.
  • The breach drew scrutiny over the mixed SHA-1/bcrypt hashing โ€” a reminder that legacy accounts often lag behind a company's improved security practices.

Why it matters

MyFitnessPal underscores two recurring lessons. First, detection lag: the breach happened weeks before the company noticed, a common pattern that lengthens exposure. Second, inconsistent password hashing โ€” mixing strong bcrypt with legacy SHA-1 โ€” means an organization is only as protected as its weakest stored credentials. The incident also cemented GnosticPlayers as one of the defining bulk-data brokers of the late-2010s, repackaging breaches like this one into sprawling multi-site dumps that fueled credential-stuffing campaigns across the consumer internet.

Timeline

  1. Attackers gain access to MyFitnessPal user data; the breach occurs during February 2018.

  2. Under Armour becomes aware that an unauthorized party acquired data associated with MyFitnessPal accounts.

  3. Under Armour publicly discloses the breach, stating roughly 150 million accounts were affected; its stock falls on the news.

  4. The company begins notifying users by email and in-app, requiring password changes.

  5. The MyFitnessPal data appears for sale on a dark-web marketplace as part of a large GnosticPlayers tranche; Have I Been Pwned adds 143.6 million accounts.

Sources

  1. haveibeenpwned.comhttps://haveibeenpwned.com/PwnedWebsites#MyFitnessPal
  2. techcrunch.comhttps://techcrunch.com/2018/03/29/under-armour-says-myfitnesspal-data-breach-affected-150-million-users/
  3. cnbc.comhttps://www.cnbc.com/2018/03/29/under-armour-stock-falls-after-company-admits-data-breach.html
  4. sec.govhttps://www.sec.gov/Archives/edgar/data/0001336917/000133691718000012/exhibit991march292018.htm
  5. zdnet.comhttps://www.zdnet.com/article/a-hacker-stole-and-published-620-million-user-records-from-16-websites/

Related incidents

Data breachContained

Quora data breach

The question-and-answer platform Quora disclosed that an unauthorized third party had accessed the data of approximately 100 million users, including names, email addresses, salted-and-hashed passwords, and imported contact and demographic data.

Victim
Quora
Records
100.0M
Data breachResolved

Exactis data exposure

Data-marketing firm Exactis left a database of nearly 340 million detailed records on individuals and businesses exposed on a publicly accessible server with no firewall. Each record held up to 400 fields of personal profiling data, from contact details to children's ages, religion, and habits.

Victim
Exactis LLC
Records
340.0M
Data breachResolved

Ticketfly data breach (2018)

In May 2018, the website for the ticket distribution service Ticketfly was defaced by an attacker and was subsequently taken offline. The attacker allegedly requested a ransom to share details of the vulnerability with Ticketfly but did not receive a reply and subsequently posted the breached dataโ€ฆ

Victim
Ticketfly
Records
26.2M