LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

Recent Breaches › Aptoide Data Breach (2020)

CRITICAL severityConfirmedHow we verify

Aptoide Data Breach (2020): What Was Exposed & What To Do

RBRecent Breaches Breach Intelligence·April 13, 2020

SourceBreach data provided in part by Have I Been Pwned, used under CC BY 4.0.

Aptoide Data Breach (2020)

Reported April 13, 2020. Approximately 20.0M people affected.

CRITICAL
Severity
20.0M
People affected
5
Data types exposed
April 13, 2020
Disclosed
ShareXLinkedInFacebookRedditWhatsAppTelegram

The Aptoide Data Breach (2020) (reported April 13, 2020) exposed Browser user agent details, Email addresses, IP addresses and Names belonging to roughly 20.0M people. If you have an account with them, your information may now be circulating on the open web and with data brokers. Here’s exactly what happened, how to check if you were affected, and what to do next.

Severity & verification
CRITICAL severityConfirmed
Account credentials exposed.
Corroborated by an official disclosure or a verified breach feed.
Was your email in the Aptoide Data Breach (2020) breach?
20.0M accounts were exposed here. See if yours is one — and every other breach it’s in. 15-sec check, no card.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

In April 2020, the independent Android app store Aptoide experienced a data breach that exposed 20 million customer records. The incident was reported on April 13, 2020, and the records were subsequently shared on a popular hacking forum. The exposed information included email addresses, names, IP addresses, browser user agent details, and passwords stored as unsalted SHA-1 hashes. For individuals whose details appeared in the dataset, the event created a lasting record of personal identifiers and credentials that could be reused in other contexts. The scale of the exposure means that a significant portion of Aptoide users now face the possibility that their account details have circulated beyond the original platform. Because the passwords were held in a format that offers limited protection, any reuse of those passwords on other services increases the chance of account takeover elsewhere.

Breaking down the breach

The breach involved 20 million customer records from Aptoide. Public reporting on April 13, 2020, stated that the data had been shared online through a hacking forum. The incident occurred in April 2020. No further details on the method of access, the duration of the intrusion, or the precise files obtained have been disclosed in available records.

How a breach like this happens

Incidents involving the exposure of user credentials and contact details often begin with an attacker gaining access to an organisation’s database or application server. Once inside, the attacker can copy stored records and later publish them on forums or file-sharing sites. In cases where passwords are protected only by unsalted hashes, automated tools can test large numbers of common passwords against the list, increasing the chance that some accounts become usable on other platforms.

Aptoide and its sector

Aptoide operates as an independent marketplace for Android applications, allowing users to discover and install apps outside the primary official store. Organisations of this type routinely collect account information such as email addresses and names to manage user profiles, along with technical details like IP addresses and browser user agents to support service delivery and security logging. A breach at such a platform is consequential because the stored data can be combined with records from other services to build more complete profiles of individuals.

What data was at risk

The records that were shared contained the following categories of information:

No additional data types have been confirmed in public reports of this incident.

What's at stake

For people whose records were included, the main practical concerns are the potential for password reuse on other accounts and the presence of their email addresses and names in datasets that may be used for targeted phishing. IP addresses and browser details can contribute to device fingerprinting over time. For the organisation, the incident adds to the body of publicly available information about its user base and the security measures applied to stored credentials.

What to do if you're exposed

Individuals can begin by changing passwords on any accounts that reuse the exposed credentials and by enabling multi-factor authentication where available. Monitoring email accounts for unexpected login attempts or password-reset messages provides an early indicator of misuse. Readers can run a free exposure scan of their email address to check whether their information has appeared in known breach datasets.

AICompiled with AI assistance from public sources and published under our editorial standards.

Editorial & sourcing policy
Recent Breaches is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data, and we do not hold the data claimed in leak-site listings. Incidents are compiled from publicly accessible sources and threat-intelligence platforms and are reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — write to support@galaxywarden.com or press@recentbreaches.com.
Check if you’re exposed →

How this breach connects

Company

Method

CompanyAptoide security record
73/100
DoxxScan™ · Moderate doxx risk
C- 64Below-average record

1 reported incident on record.

See Aptoide’s full breach history →

More recent breaches

MEO Data Breach (2020)December 24, 2020NetGalley Data Breach (2020)December 21, 2020MMG Fusion Data Breach (2020)December 20, 2020DriveSure Data Breach (2020)December 19, 2020

Latest breaches

Read GalaxyWarden’s full analysis of the Aptoide Data Breach (2020) →

Verified breach. Breach data provided in part by Have I Been Pwned, used under CC BY 4.0.

Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.

Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.

ShareXLinkedInFacebookRedditWhatsAppTelegram