Popular fishing app Fishbrain is investigating a data breach that exposed users’ personal information alongside password hashes and salts, raising the risk of credential cracking and follow-on attacks.[1][2][10][12]
According to a breach notification filed with the California Attorney General, Fishbrain AB discovered on August 19, 2026 that an unauthorized party had accessed its systems, with activity believed to have started as early as July 30.[2][7][10][12] The sample notice and associated summaries state that exposed data includes names, dates of birth, email addresses, phone numbers, Fishbrain usernames, country information, password hashes, and salts.[1][2][10] The company, which says it serves more than 20 million anglers worldwide, has not disclosed how many accounts were affected, and incident trackers list the number of records as “not disclosed.”[1][3][6]
Fishbrain’s notification stresses that passwords were not stored in plaintext, but acknowledges that compromised hashes for some users “may be susceptible to being decoded,” a warning that reflects concern over offline cracking if the underlying password and hashing parameters are weak.[1][4] Security guidance such as NIST Special Publication 800‑63B notes that salted, hashed password storage remains vulnerable if attackers can run large volumes of guesses against stolen hashes, and recommends using cost-intensive key derivation functions and strong, unique passwords to make such attacks prohibitively expensive.[15] Fishbrain has not publicly detailed which hashing algorithm or configuration was in use, leaving users without clear visibility into the practical difficulty of cracking their individual credentials.[1][4]
Regulatory filings show Fishbrain submitted its sample breach notice to the California Attorney General in early September, as required when more than 500 state residents receive incident notifications, placing the disclosure roughly two weeks after the intrusion was detected.[2][3][9][12] Breach trackers and law firm notices summarizing the case reiterate that the exposed dataset centers on contact and identity information plus authentication material, but they do not report any confirmed misuse of the stolen data or attribute the attack to a specific threat actor at this time.[5][7][10][12] Without evidence of exploitation in the wild or technical details of the vulnerability that was abused, external observers have limited ability to independently assess the likelihood of credential compromise and account takeover stemming from this incident.[1][6][12]
In response, Fishbrain says it has patched the vulnerability that enabled the intrusion, restricted access to the affected environment, strengthened its security controls, and initiated a broader review of its data protection measures while the investigation continues.[1][4][7] The company also reports that it has reset passwords for all users as a precaution, requiring customers to choose a new password the next time they sign in to the service.[1][4] This platform-wide reset is intended to reduce the window in which cracked hashes could be used to access Fishbrain accounts, even if some credentials are eventually recovered by attackers.[1][10]
Users are being urged to change any other online passwords that match or resemble their former Fishbrain credentials, and to pay close attention to suspicious emails, texts, or calls that could leverage exposed personal data for phishing or social engineering.[1][4][5][7][10] Consumer-focused breach notices and trackers covering the incident recommend adopting strong, unique passwords for every account, storing them in a password manager, and enabling multi-factor authentication wherever possible to blunt the impact of compromised credentials.[5][7][10][12][15] Until Fishbrain and regulators release more detail on the scope and technical root cause of the breach, affected anglers should assume their data could be in circulation and take defensive steps across any services that share usernames, email addresses, or login patterns with their Fishbrain profile.[1][2][10][12]
References
- Cybercrooks trawl Fishbrain to net password hashes
- Submitted Breach Notification Sample | State of California
- Search Data Security Breaches | State of California
- Киберпреступники похитили хеши паролей и соли пользователей Fishbrain
- Fishbrain AB Data Breach Notice (California Attorney …
- Cybersecurity Incident Tracker
- Data Breach News
- Data Security Breach Reporting – California Department of Justice
- Current Data Breaches Archive
- Recent Breaches: Latest Data Breach News & Live Tracker (2026)
- NIST Special Publication 800-63B