LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

Recent Breaches › Flat Earth Sun, Moon and Zodiac App Data Breach (2024)

HIGH severityConfirmedHow we verify

Flat Earth Sun, Moon and Zodiac App Data Breach (2024): What Was Exposed & What To Do

RBRecent Breaches Breach Intelligence·October 15, 2024

SourceBreach data provided in part by Have I Been Pwned, used under CC BY 4.0.

Flat Earth Sun, Moon and Zodiac App Data Breach (2024)

Reported October 15, 2024. Approximately 33K people affected.

HIGH
Severity
33K
People affected
8
Data types exposed
October 15, 2024
Disclosed
ShareXLinkedInFacebookRedditWhatsAppTelegram

Flat Earth Sun, Moon and Zodiac App Data Breach (2024) was disclosed on October 15, 2024, exposing records of 33,000 individuals that included dates of birth, email addresses, genders, geographic locations, and latitude/longitude pairs. If you used the app, review your account settings and consider changing passwords or enabling additional account protections.

Severity & verification
HIGH severityConfirmed
Account credentials exposed.
Corroborated by an official disclosure or a verified breach feed.
Was your email in the Flat Earth Sun, Moon and Zodiac App Data Breach (2024) breach?
33K accounts were exposed here. See if yours is one — and every other breach it’s in. 15-sec check, no card.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

In October 2024, roughly 33,000 people who used the Flat Earth Sun, Moon and Zodiac App learned that extensive personal details tied to their accounts had been exposed. For those users the practical stakes are immediate: email addresses, usernames, plain-text passwords and precise geographic coordinates can be combined to enable account takeovers, targeted phishing or unwanted contact. Even a modest set of additional fields—names, dates of birth and genders on a smaller number of profiles—raises the risk of identity-related misuse.

Public reporting places the discovery in mid-October 2024. The incident matters because the data set is not abstract; it links digital identities to real-world locations and credentials that many people reuse across services. Understanding what is known, what remains undisclosed, and what steps affected individuals can take is the purpose of this account.

Inside the incident

According to the reported summary, the Flat Earth Sun, Moon and Zodiac App, created by Flat Earth Dave, was found in October 2024 to be leaking extensive personal information of its users. The data included 33,000 unique email addresses together with usernames, latitudes and longitudes describing users’ positions on the globe, and passwords stored in plain text. A small number of profiles also contained names, dates of birth and genders. The breach was reported on 15 October 2024. No further public detail has been provided on the precise technical method of exposure, the duration of the leak, or whether the data was actively exploited after discovery. Scale is stated as 33,000 people; other metrics such as total records or financial impact remain undisclosed.

How a breach like this happens

Incidents that expose user databases typically begin with an unprotected or misconfigured storage location, an unpatched application vulnerability, or credentials that grant unintended access to backend systems. Once an attacker or researcher gains a foothold, bulk extraction of account tables is common. When passwords are stored without hashing or encryption—as the facts state occurred here—the extracted credentials can be used immediately against the original service and against any other site where the same password was reused. Geographic coordinates and email addresses add further value for social-engineering or location-based targeting. No specific threat actor has been attributed in the available record, so the precise pathway remains unconfirmed; the pattern, however, is familiar across many consumer applications that collect location and identity data.

Flat Earth Sun, Moon and Zodiac App and its sector

The Flat Earth Sun, Moon and Zodiac App is a niche consumer application serving users interested in flat-earth cosmology, solar and lunar tracking, and zodiac-related content. Apps in this sector ordinarily collect account credentials, optional profile details and, because of the subject matter, location data that helps display celestial or geographic information. Such applications sit within the broader mobile and web-app ecosystem, where user bases may be modest yet the data collected can be highly personal. A breach is consequential because the combination of precise latitude-longitude pairs with reusable passwords and contact information can expose individuals who may already feel socially or professionally sensitive about their beliefs. The organisation itself faces reputational and operational consequences typical of any service that loses control of user records.

The information in question

The facts name the following data types as exposed: dates of birth, email addresses, genders, geographic locations, latitude and longitude pairs, names, passwords and usernames. The reported summary confirms that the bulk of the 33,000 records contained email addresses, usernames, latitudes and longitudes, and plain-text passwords; names, dates of birth and genders appeared on only a smaller subset of profiles. Exact contents beyond these categories are unconfirmed. Organisations of this kind commonly hold additional fields such as device identifiers or usage logs, but those elements are not listed in the public facts and therefore cannot be asserted as part of this incident.

The real-world impact

For affected individuals the most concrete risks are credential stuffing—where the plain-text passwords are tried against email, banking or social-media accounts—and phishing campaigns that reference the user’s known location or username to appear legitimate. Precise geographic coordinates can also enable physical-world harassment or unwanted attention, particularly for users who prefer privacy around their views. Identity-related fraud is possible where names, dates of birth and genders were present, though the facts indicate these fields were limited to a minority of profiles. For the organisation the consequences include loss of user trust, potential regulatory scrutiny under data-protection rules, and the operational cost of notifying users and securing systems. No dollar figures or confirmed secondary attacks have been reported.

Were you affected?

If you ever registered for the Flat Earth Sun, Moon and Zodiac App, treat the associated email address and password as compromised. Change that password immediately on the app (if still accessible) and on every other service where you reused it. Enable multi-factor authentication wherever available, monitor email for unexpected login alerts or password-reset messages, and remain alert to phishing that references flat-earth or zodiac themes. Readers can also run a free exposure scan of their email address to check whether their information has already surfaced in known breach data sets. Public detail on remediation steps taken by the app’s operator remains limited; individuals should therefore assume responsibility for their own credential hygiene until further official guidance appears.

AICompiled with AI assistance from public sources and published under our editorial standards.

Editorial & sourcing policy
Recent Breaches is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data, and we do not hold the data claimed in leak-site listings. Incidents are compiled from publicly accessible sources and threat-intelligence platforms and are reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — write to support@galaxywarden.com or press@recentbreaches.com.
Check if you’re exposed →

How this breach connects

Method

More recent breaches

1win Data Breach (2024)November 2, 2024Instituto Nacional de Deportes de Chile Data Breach (2024)September 12, 2024Synthient Credential Stuffing Threat Data Data Breach (2025)April 11, 2025BitView Data Breach (2024)December 14, 2024

Latest breaches

Read GalaxyWarden’s full analysis of the Flat Earth Sun, Moon and Zodiac App Data Breach (2024) →

Verified breach. Breach data provided in part by Have I Been Pwned, used under CC BY 4.0.

Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.

Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.

ShareXLinkedInFacebookRedditWhatsAppTelegram