150m MyFitnessPal users hit by data breach

Thieves made off with usernames, email addresses and encrypted passwords

Health and fitness app MyFitnessPal has been hit by one of the biggest data breaches in history, after cyber thieves made off with the personal data of around 150 million users.

Under Armour, the activewear brand that owns and operates the app, confirmed last week that usernames, email addresses and hashed passwords were all stolen in the breach. The company has said that the majority of the affected passwords were encrypted with the Bcrypt algorithm, which has a good reputation for security.

The breach occurred in February and was detected on 25 March. MyFitnessPal has notified users, and will be requiring all affected accounts to change their passwords.

"We take our obligation to safeguard your personal data very seriously and are alerting you about this issue so you can take steps to help protect your information," the company said as part of an announcement notifying customers of the breach.

"Once we became aware, we quickly took steps to determine the nature and scope of the issue. We are working with leading data security firms to assist in our investigation. We have also notified and are coordinating with law enforcement authorities."

Advertisement
Advertisement - Article continues below
Advertisement - Article continues below

The hack is the third-biggest breach in history when measured by volume of affected accounts. Over 3 billion accounts were compromised by two record-shattering Yahoo breaches in 2013 and 2014, while 412 million users were hit by the breach of AdultFriendFinder and other sites under the FriendFinder Networks banner.

Under Armour purchased MyFitnessPal for $475 million back in 2015, and the app is part of the company's IoT and connected fitness portfolio.

Featured Resources

Digitally perfecting the supply chain

How new technologies are being leveraged to transform the manufacturing supply chain

Download now

Three keys to maximise application migration and modernisation success

Harness the benefits that modernised applications can offer

Download now

Your enterprise cloud solutions guide

Infrastructure designed to meet your company's IT needs for next-generation cloud applications

Download now

The 3 approaches of Breach and Attack Simulation technologies

A guide to the nuances of BAS, helping you stay one step ahead of cyber criminals

Download now
Advertisement

Recommended

Visit/security/internet-security/354417/avast-and-avg-extensions-pulled-from-chrome
internet security

Avast and AVG extensions pulled from Chrome

19 Dec 2019
Visit/security/354156/google-confirms-android-cameras-can-be-hijacked-to-spy-on-you
Security

Google confirms Android cameras can be hijacked to spy on you

20 Nov 2019

Most Popular

Visit/operating-systems/25802/17-windows-10-problems-and-how-to-fix-them
operating systems

17 Windows 10 problems - and how to fix them

13 Jan 2020
Visit/microsoft-windows/32066/what-to-do-if-youre-still-running-windows-7
Microsoft Windows

What to do if you're still running Windows 7

14 Jan 2020
Visit/web-browser/30394/what-is-http-error-503-and-how-do-you-fix-it
web browser

What is HTTP error 503 and how do you fix it?

7 Jan 2020
Visit/policy-legislation/general-data-protection-regulation-gdpr/354577/data-protection-fines-hit-ps100m
General Data Protection Regulation (GDPR)

Data protection fines hit £100m during first 18 months of GDPR

20 Jan 2020