Skip to main content
Emerging ThreatsData Breaches

Fishbrain Breach Exposes Password Hashes to Cyberattack Risks

Smartphone on a cluttered desk with papers and a pen in a quiet daytime setting.

"Fishbrain passwords were not stored in plaintext; however, Fishbrain has determined that the compromised password hashes for some users may be susceptible to being decoded," Fishbrain said in its disclosure to the California Attorney General's Office.

What Fishbrain told regulators and users

Fishbrain AB — which the company says operates an app used by more than 20 million anglers — reported an intrusion that occurred on August 19 and disclosed the incident to the California Attorney General's Office this week. The company said unknown perpetrators accessed a trove of user data that included names, dates of birth, email addresses, phone numbers, Fishbrain usernames, country information, and critically, password hashes and salts.

Password hashes, salts and the practical risk

Fishbrain confirmed that passwords were not kept in plaintext, but warned that some of the compromised password hashes "may be susceptible to being decoded." The Register's report notes that, with hashes and salts in hand, attackers can run password-guessing attempts on their own hardware until they potentially recover original credentials. Success in those attempts depends on two variables Fishbrain did not disclose: the strength of individual passwords and the hashing algorithm used to protect them.

How Fishbrain responded immediately

According to the company, after discovering the intrusion and carrying out an initial forensic investigation, Fishbrain patched the vulnerability and reset every user's password. Customers are required to create a new password the next time they log in. Fishbrain also said it "restricted access to the affected environment," strengthened security controls, and initiated "a broader review of our data security measures" while the investigation continues. The Register asked Fishbrain for additional information; the company did not provide details on the scale of the breach or how many of its 20 million-plus users were affected.

Risks to users: credential reuse and phishing

Fishbrain's disclosure included direct advice to users: if you use your Fishbrain password for any other online accounts, "you should promptly update those passwords and any associated security questions or answers." It added: "You should also take other appropriate steps to protect any online accounts that use the same username or email address and password combination. We recommend using a strong, unique password for each of your accounts." The report ends with an admonition aimed at the community: watch for phisherfolk using stolen personal data to bait follow-on attacks.

What this means for technologists, the California Attorney General, and Fishbrain users

  • Technologists and security teams: They will want to confirm which hashing algorithm was in use because Fishbrain did not disclose it, and they will note the company’s actions — patching the vulnerability, restricting access to the affected environment, resetting all passwords, and launching a broader security review — as immediate mitigation steps.
  • The California Attorney General’s Office: The office has received Fishbrain’s notification, creating a formal record of the incident under state breach-notification procedures; regulators now have the disclosure on file while the company continues its investigation.
  • Fishbrain users: Anyone who reuses credentials across services should assume those reused credentials may be at risk, update passwords and security questions where applicable, and remain alert for phishing that leverages the personal data exposed in this intrusion.

Fishbrain has taken the common first steps after a data exposure: containment, forced password resets, and an internal review. What remains unsettled — and will shape the risk to individual accounts — is how easily the stolen hashes and salts can be decoded, a question the company has not answered and that depends on both password strength and the undisclosed hashing algorithm. As investigators continue their work, the immediate, concrete action for affected users is straightforward: change reused passwords, enable any available account protections, and treat unsolicited communications with extra skepticism.

Original report: The Register