Cybercrooks trawl Fishbrain to net password hashes
- ID
- 21048
- Status
- summarized
- Published
- 03 Sep 2026, 8:45 PM
- Fetched
- 03 Sep 2026, 9:28 PM
- Provider
- The Register
- Category
- technology
- Original URL
- https://www.theregister.com/cyber-crime/2026/09/03/cybercrooks-trawl-fishbrain-to-net-password-hashes/5294158
- Source URL
- https://www.theregister.com/headlines.atom
Summary
- Score
- 3.5
- Created
- 03 Sep 2026, 9:30 PM
- Tags
- Audience
- developerssaas_founders
What happened
Fishing app Fishbrain, which claims 20M+ users, disclosed an August 19 breach where attackers stole names, DOBs, emails, phone numbers, usernames, country info, password hashes, and salts. The company did not disclose the hashing algorithm, the number of affected users, or how the breach occurred, but has patched the vulnerability and force-reset all passwords.
Why it matters
A consumer app breach with hashes and salts exfiltrated is a reminder to verify your own auth stack uses a slow, memory-hard KDF (bcrypt, scrypt, Argon2) with per-user salts — not just 'not plaintext.' If you ship a SaaS or app with user accounts, this is the exact scenario where weak hashing turns a breach into full credential exposure. No Malaysia-specific angle here.
Discussion angle
Quick check: what hashing algorithm does your current project use, and would your hashes survive an offline cracking attempt if salts were also stolen? If you can't answer instantly, that's the takeaway.