• Home
  • News
  • Coins2Day 500
  • Tech
  • Finance
  • Leadership
  • Lifestyle
  • Rankings
  • Multimedia
data breach

Hacked MyFitnessPal Data Goes on Sale on the Dark Web—One Year After the Breach

By
Alyssa Newcomb
Alyssa Newcomb
Down Arrow Button Icon
By
Alyssa Newcomb
Alyssa Newcomb
Down Arrow Button Icon
February 14, 2019, 5:57 PM ET

The MyFitnessPal app disclosed a data breach last year affecting as many as 150 million users. Now, some of those stolen credentials are popping up for sale on the dark web.

Not only is data from Under Armour’s MyFitnessPal, a diet and exercise community, being offered, but hackers also have their hands on credentials from 15 other websites. The asking price: Less than $20,000 in Bitcoin, according to a report from The Register.

Erin Wendell, a spokesperson for MyFitnessPal, said users were required to change their passwords after the breach was reported last March, so any stolen credentials are no longer valid on the site.

“We responded swiftly to alert users and have since required all MyFitnessPal users who had not changed their passwords since that March 29, 2018 announcement, to reset their passwords. As a result, passwords previously used for MyFitnessPal at the time of the data security issue are no longer valid on MyFitnessPal, and we continue to encourage strong password practices including unique and complex passwords for all their accounts to enable users to further protect themselves,” she said.

While it doesn’t sound like hackers will be able to check on what MyFitnessPal users ate for breakfast, the leaked credentials could be a problem for people who reuse passwords across multiple websites. The passwords appear to be hashed and encrypted, however a buyer could cross-reference breached email addresses with previous hacks to see if someone reused a password.

Another website included in the Valentine’s Day fire sale, the dating app Coffee Meets Bagel, sent users an email on Thursday to notify them that they learned of a breach on February 11, the same day The Register‘s report was published. A partial list of names and email addresses are believed to be the only information compromised. The email did not say how many users may have been exposed.

The other websites mentioned in The Register’ s report are: Dubsmash, MyHeritage, ShareThis, HauteLook, Animoto, EyeEm, 8fit, Whitepages, Fotolog, 500px, Armor Games, BookMate, Artsy, and DataCamp.

One way to quickly check to see if your credentials have been breached is to enter your email address at HaveIBeenPwned.com. While the site doesn’t say where your data was leaked, it can tell you how many data dumps include your email address. Whether you’ve been “pwned” or not, security experts also recommend that you regularly change your passwords and use one unique password per site.

About the Author
By Alyssa Newcomb
See full bioRight Arrow Button Icon
Rankings
  • 100 Best Companies
  • Coins2Day 500
  • Global 500
  • Coins2Day 500 Europe
  • Most Powerful Women
  • Future 50
  • World’s Most Admired Companies
  • See All Rankings
Sections
  • Finance
  • Leadership
  • Success
  • Tech
  • Asia
  • Europe
  • Environment
  • Coins2Day Crypto
  • Health
  • Retail
  • Lifestyle
  • Politics
  • Newsletters
  • Magazine
  • Features
  • Commentary
  • Mpw
  • CEO Initiative
  • Conferences
  • Personal Finance
  • Education
Customer Support
  • Frequently Asked Questions
  • Customer Service Portal
  • Privacy Policy
  • Terms Of Use
  • Single Issues For Purchase
  • International Print
Commercial Services
  • Advertising
  • Coins2Day Brand Studio
  • Coins2Day Analytics
  • Coins2Day Conferences
  • Business Development
About Us
  • About Us
  • Editorial Calendar
  • Press Center
  • Work At Coins2Day
  • Diversity And Inclusion
  • Terms And Conditions
  • Site Map

© 2025 Coins2Day Media IP Limited. All Rights Reserved. Use of this site constitutes acceptance of our Terms of Use and Privacy Policy | CA Notice at Collection and Privacy Notice | Do Not Sell/Share My Personal Information
FORTUNE is a trademark of Coins2Day Media IP Limited, registered in the U.S. and other countries. FORTUNE may receive compensation for some links to products and services on this website. Offers may be subject to change without notice.