Dating App MobiFriends Experienced Data Breach Affecting 3.6 Million Users

MobiFriends is a dating app based in Barcelona, Spain. It was revealed that hackers managed to hack and leak the personal details of 3,688,060 of its users.

The hackers posted the data online and made them available for sale on dark web forums. In some cases, the data is also made free to download.

While the data does not contain any private messages, images, or sexual-related content, the data does include other types of sensitive details, such as email addresses, mobile numbers, dates of birth, gender information, usernames, and user activity while using the service.

Furthermore, passwords are also included.

MobiFriends

"Moreover, the data leak contains professional email addresses related to well-known entities including: American International Group (AIG), Experian, Walmart, Virgin Media, and a number of other F1000 companies," the researchers said.

And making matters worse, the passwords have been secured with MD5, a hashing function considered weak in the modern days standard.

The data was obtained in a security breach that took place in January 2019, according to a hacker who initially put the data up the data on a hacking forum.

The incident was discovered by Risk Based Security. In a blog post, the researchers said that:

"The compromised data sets were originally posted for sale on a prominent deep web hacking forum on January 12th, 2020 by a threat actor named 'DonJuji' and attributed to a January 2019 breach event. They were later shared in a non-restricted manner on April 12th, 2020 by a different threat actor on the same forum."

The researchers said that they verified the validity of the data against the official MobiFriends website.

[block:block=87]

MobiFriends is a popular dating application designed to let users meet new people online. According to LinkedIn, the service was founded in 2005 and has up to 50 employees.

At the moment of announcement, the researchers have yet to know how the app's user data was obtained. The researchers have no clear idea about how the hackers managed to exploit a vulnerability in a server or API, or if MobiFriends left a database exposed online without a password.

Regardless, affected users are becoming vulnerable to spear-phishing attacks or extortion attempts.

Furthermore, the username, email, and password combinations obtained from the breach can also be used for brute-force attack attempts to target accounts on other websites where MobiFriends users might have reused the credentials.

MobiFriends

According to Roy Bass, senior dark web analyst at Risk Based Security:

“It leaves certain users open to spear-phishing or targeted extortion, as we saw a number of professional email addresses in the data."

"Furthermore, the exposure of user credentials allows threat actors to check them against other websites in a brute-force fashion. If the credentials have been re-used, the threat actors may be able to gain access to more valuable accounts i.e. banking accounts, social media accounts, etc."

And because the data also includes date of birth and phone number, Bass added that:

"It is possible for threat actors to use this data in conjunction with other data breaches to have a wide range of compromised data on an individual. If enough valuable information is compiled it could be sold and/or later used for identity theft, extortion, and other malicious campaigns."

With this incident, users are advised to change passwords on every account where they use the same login details as the MobiFriends app.