MobiFriends Data Breach (2020): What Was Exposed & What To Do
SourceBreach data provided in part by Have I Been Pwned, used under CC BY 4.0.
The MobiFriends Data Breach (2020) (reported January 6, 2020) exposed Dates of birth, Email addresses, Genders and Passwords belonging to roughly 3.5M people. If you have an account with them, your information may now be circulating on the open web and with data brokers. Here’s exactly what happened, how to check if you were affected, and what to do next.
What happened
In January 2020 the Barcelona-based dating service MobiFriends experienced a data breach. Public records of the incident state that 3.5 million unique email addresses were exposed along with usernames, genders, dates of birth and MD5 password hashes. The breach was reported on 6 January 2020. No further details on the method of access, the exact date range of the intrusion or any subsequent actions by the organisation have been disclosed in the available reporting.
How a breach like this happens
Incidents involving the exposure of user account data from online services commonly occur when an attacker obtains unauthorised access to a company’s database or backup storage. This can result from remote exploitation of software vulnerabilities, compromised administrative credentials or misconfigured servers that leave data accessible. Once obtained, the information may be copied and later circulated. In many cases the organisation learns of the event only after the data appears on public forums or is offered for sale.
MobiFriends and its sector
MobiFriends operated as a dating application serving users primarily in Europe. Services of this type collect and store account credentials, contact details and demographic information to enable profile matching and communication between users. A breach at such a platform is consequential because the data often includes identifiers that people prefer to keep private and because password hashes, even when not stored in plain text, can be subject to offline attempts at recovery.
The information in question
The records associated with the incident list the following categories of information as having been exposed: email addresses, usernames, genders, dates of birth and MD5 password hashes. No additional categories or confirmation of the completeness of the data set have been provided in public reports.
What's at stake
For individuals, the presence of an email address alongside a date of birth and a password hash can increase the chance of targeted account takeover attempts on other services that reuse the same credentials. The disclosure of gender and date of birth can also contribute to more accurate profiling when combined with other available data sources. For the organisation, the event creates legal, regulatory and reputational obligations related to user notification and security improvements.
Were you affected?
Individuals can take several immediate steps if they believe their information may have been included. First, change the password on the MobiFriends account and on any other service that uses the same or a similar password. Second, enable multi-factor authentication wherever it is offered. Third, monitor email accounts for unusual login attempts or unsolicited messages.
- Review account activity on any service that shares the exposed email address.
- Consider using a password manager to generate and store unique credentials.
- Run a free exposure scan of the email address against known breach data sets to check for additional appearances.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
MEO Data Breach (2020)NetGalley Data Breach (2020)MMG Fusion Data Breach (2020)DriveSure Data Breach (2020)Latest breaches
Read GalaxyWarden’s full analysis of the MobiFriends Data Breach (2020) →
Verified breach. Breach data provided in part by Have I Been Pwned, used under CC BY 4.0.
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.