LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

Recent Breaches › MobiFriends Data Breach (2020)

CRITICAL severityConfirmedHow we verify

MobiFriends Data Breach (2020): What Was Exposed & What To Do

RBRecent Breaches Breach Intelligence·January 6, 2020

SourceBreach data provided in part by Have I Been Pwned, used under CC BY 4.0.

MobiFriends Data Breach (2020)

Reported January 6, 2020. Approximately 3.5M people affected.

CRITICAL
Severity
3.5M
People affected
5
Data types exposed
January 6, 2020
Disclosed
ShareXLinkedInFacebookRedditWhatsAppTelegram

The MobiFriends Data Breach (2020) (reported January 6, 2020) exposed Dates of birth, Email addresses, Genders and Passwords belonging to roughly 3.5M people. If you have an account with them, your information may now be circulating on the open web and with data brokers. Here’s exactly what happened, how to check if you were affected, and what to do next.

Severity & verification
CRITICAL severityConfirmed
Account credentials exposed.
Corroborated by an official disclosure or a verified breach feed.
Was your email in the MobiFriends Data Breach (2020) breach?
3.5M accounts were exposed here. See if yours is one — and every other breach it’s in. 15-sec check, no card.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

People who signed up for the MobiFriends dating app may have had email addresses, usernames, dates of birth, genders and password hashes exposed without their knowledge. The incident, reported on 6 January 2020, involved 3.5 million unique email addresses and remains one of the documented cases in which personal details from a dating platform became publicly available.

What happened

In January 2020 the Barcelona-based dating service MobiFriends experienced a data breach. Public records of the incident state that 3.5 million unique email addresses were exposed along with usernames, genders, dates of birth and MD5 password hashes. The breach was reported on 6 January 2020. No further details on the method of access, the exact date range of the intrusion or any subsequent actions by the organisation have been disclosed in the available reporting.

How a breach like this happens

Incidents involving the exposure of user account data from online services commonly occur when an attacker obtains unauthorised access to a company’s database or backup storage. This can result from remote exploitation of software vulnerabilities, compromised administrative credentials or misconfigured servers that leave data accessible. Once obtained, the information may be copied and later circulated. In many cases the organisation learns of the event only after the data appears on public forums or is offered for sale.

MobiFriends and its sector

MobiFriends operated as a dating application serving users primarily in Europe. Services of this type collect and store account credentials, contact details and demographic information to enable profile matching and communication between users. A breach at such a platform is consequential because the data often includes identifiers that people prefer to keep private and because password hashes, even when not stored in plain text, can be subject to offline attempts at recovery.

The information in question

The records associated with the incident list the following categories of information as having been exposed: email addresses, usernames, genders, dates of birth and MD5 password hashes. No additional categories or confirmation of the completeness of the data set have been provided in public reports.

What's at stake

For individuals, the presence of an email address alongside a date of birth and a password hash can increase the chance of targeted account takeover attempts on other services that reuse the same credentials. The disclosure of gender and date of birth can also contribute to more accurate profiling when combined with other available data sources. For the organisation, the event creates legal, regulatory and reputational obligations related to user notification and security improvements.

Were you affected?

Individuals can take several immediate steps if they believe their information may have been included. First, change the password on the MobiFriends account and on any other service that uses the same or a similar password. Second, enable multi-factor authentication wherever it is offered. Third, monitor email accounts for unusual login attempts or unsolicited messages.

AICompiled with AI assistance from public sources and published under our editorial standards.

Editorial & sourcing policy
Recent Breaches is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data, and we do not hold the data claimed in leak-site listings. Incidents are compiled from publicly accessible sources and threat-intelligence platforms and are reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — write to support@galaxywarden.com or press@recentbreaches.com.
Check if you’re exposed →

How this breach connects

Company

Method

CompanyMobiFriends security record
73/100
DoxxScan™ · Moderate doxx risk
C- 64Below-average record

1 reported incident on record.

See MobiFriends’s full breach history →

More recent breaches

MEO Data Breach (2020)December 24, 2020NetGalley Data Breach (2020)December 21, 2020MMG Fusion Data Breach (2020)December 20, 2020DriveSure Data Breach (2020)December 19, 2020

Latest breaches

Read GalaxyWarden’s full analysis of the MobiFriends Data Breach (2020) →

Verified breach. Breach data provided in part by Have I Been Pwned, used under CC BY 4.0.

Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.

Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.

ShareXLinkedInFacebookRedditWhatsAppTelegram