2026 Fishbrain — Jul 30 unauthorized access to user-data environment; names/emails/password hashes (CA AG)
Data compromised
First and last name, email address, telephone number, Fishbrain username, country, password hash and salt, and date of birth; company says hashes for some users may be susceptible to decoding; passwords not stored in plaintext
Technical writeup
Verified company notice via California Attorney General filing sb24-629190 — reported September 2, 2026. Stockholm-based fishing social app Fishbrain AB wrote users that on August 19, 2026 it discovered unauthorized access to an environment used to host user data and that on August 24 it determined login-credential-related information had been accessed; investigation indicated unauthorized access began as early as July 30, 2026. Exposed fields include names, emails, phone numbers, usernames, country, dates of birth, and password hashes with salts. Fishbrain said passwords were not stored in plaintext but that some hashes may be susceptible to decoding; it patched the vulnerability, restricted access, reset affected passwords, and terminated active sessions. No nationwide victim count was stated in the CA sample notice (CA filings require notices only when ≥500 California residents are notified). recordsAffected 0 pending attested census; companyConfirmed true.
Root cause
Unauthorized access to a Fishbrain environment hosting user data beginning as early as July 30, 2026; discovered August 19 and confirmed August 24 per company California AG notice