[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f222i1cjbnxe5t":3},{"success":4,"breach":5},true,{"_id":6,"name":7,"title":8,"slug":9,"domain":10,"breachDate":11,"addedDate":12,"modifiedDate":13,"contentUpdatedAt":14,"source":15,"sourceUrl":16,"sourceUrls":17,"pwnCount":18,"affectedCount":18,"affectedCountStatus":19,"affectedCountLowerBound":20,"affectedCountUnit":21,"hasEnglishDescription":4,"severity":22,"dataClasses":23,"description":32,"seoTitle":16,"seoTitleEn":8,"seoDescription":16,"seoDescriptionEn":33,"logoUrl":34,"isVerified":4,"isSensitive":4,"isSpamList":35,"isMalware":35,"company":36},"68e3266eda11adda488251d7","flat-earth-dave","Flat Earth Sun, Moon and Zodiac App Data Breach","flat-earth-sun-moon-and-zodiac-app","flatearthdave.com","2024-10-15T00:00:00.000Z","2025-03-02T05:12:30.000Z","2025-03-02T05:31:09.000Z","2026-07-18T23:50:57.665Z","Third party breach","",[],33294,"known",null,"unknown","Medium",[24,25,26,27,28,29,30,31],"Dates of birth","Email addresses","Genders","Geographic locations","Latitude and longitude pairs","Names","Passwords","Usernames","\u003Cp>Flat Earth Sun, Moon and Zodiac App is a niche mobile application created by Flat Earth Dave. In October 2024, it was reported that the app exposed user data; 33,000 unique email addresses, usernames, latitude-longitude information, and plain text passwords were affected.\u003C\u002Fp>\u003Cp>This record is highly sensitive due to plain text passwords and precise location information. Additional fields such as name, date of birth, and gender were also found in a small profile section. Therefore, the incident should be considered not only as a niche application account but also taking into account identity, location, and password security together.\u003C\u002Fp>\u003Ch2>Leaked Data Types and Risks\u003C\u002Fh2>\u003Cp>The data classes tracked in the Flat Earth Sun, Moon and Zodiac App registration should be considered as birth dates, email addresses, gender information, geographic locations, latitude and longitude pairs, full name information, password data, and usernames. Birth dates are permanent personal data that can be used in authentication questions, age-based targeting, and profile enrichment. Email addresses can be used for targeted phishing, password reset schemes, and account matching across different services. Gender information can provide additional personalization context in profile inference and targeted messages. Geographic location information can indicate the user's area, making local campaigns or service pretexts more convincing.Latitude and longitude pairs carry precise location context, so they pose a higher privacy risk than general location information. Name and surname information makes fake support, fake donations, fake deliveries, or customer service messages more convincing. Password data directly increases the risk of account takeover, especially if the same password is reused on other services. Usernames can help link pseudonyms across different platforms and personalize social engineering messages.\u003C\u002Fp>\u003Cp>A plain text password can be tried on other accounts without requiring a cracking process. Since latitude and longitude information can be associated with the user's real location, the privacy risk is high; the username and email can link this location to the online identity.\u003C\u002Fp>\u003Ch2>Verified Scope and Boundaries\u003C\u002Fh2>\u003Cp>This record is associated with the flatearthdave.com domain name and the October 2024 app incident. The scope includes date of birth, email, gender, geographic location, latitude-longitude, name, plaintext password, and usernames. Payment or private message fields are not verified for this record.\u003C\u002Fp>\u003Cp>Fields not present in this record should not be described as if they were leaked. Full payment card, bank information, official ID, private message, health data, student file, password, or financial data should only be included in the risk assessment if they are explicitly present in the record. The text is based on verifiable data classes and the known boundaries of the incident.\u003C\u002Fp>\u003Ch2>User Groups at Risk\u003C\u002Fh2>\u003Cp>People who use the application, users who use the same username on other platforms, those who reuse their plaintext password on other accounts, and individuals for whom location privacy is important are at higher risk.\u003C\u002Fp>\u003Cp>Users who use the same email address across different services, repeat their old passwords, share their phone and address information on many platforms, or use their real identity openly in community\u002Fevent accounts are at higher risk. The privacy impact in records with political, student, or official identity context can be heavier than in normal commercial records.\u003C\u002Fp>\u003Ch2>Urgent Measures to Be Taken\u003C\u002Fh2>\u003Cp>Users should immediately change the password they use in the app and all accounts where the same password is used. Connections between usernames and social media profiles should also be reviewed due to location information.\u003C\u002Fp>\u003Cp>Users in the positive match area should update their passwords on accounts where they use the same or similar passwords, enable two-factor authentication where possible, and check recent sessions. Records that do not contain passwords but include contact, donation, address, event, or student data should be monitored for unexpected calls, offers, support, and verification messages.\u003C\u002Fp>\u003Ch2>Long-Term Security Strategies\u003C\u002Fh2>\u003Cp>In the long term, the habit of using a password manager, unique passwords, two-factor authentication, and removing unnecessary personal information from accounts reduces risk. Reusing the same email address across different platforms makes it easier to combine data from different breaches; using a separate email or alias for critical accounts can be considered.\u003C\u002Fp>\u003Cp>Even in niche applications, sensitive location and password data may be present. Users should regularly check applications that request location permissions and must use unique passwords for each application due to the risk of plain text passwords.\u003C\u002Fp>\u003Ch2>Record Control and User Action\u003C\u002Fh2>\u003Cp>LeakData check indicates whether the queried email address is present in this record. A positive result does not necessarily mean that all data fields definitely belong to that user; however, it is a sufficient warning for precautionary measures. A negative result only indicates that there is no match in this dataset and does not eliminate the possibility of appearing in other breaches.\u003C\u002Fp>\u003Cp>A positive result indicates that the email address is found in the records of the Flat Earth Sun, Moon and Zodiac App. Due to the plain text password and precise location context, the result requires high-priority action.\u003C\u002Fp>","Flat Earth Sun, Moon and Zodiac App Data Breach. 33.3 Thousand reported records were reported. Reported data: Dates of birth, Email addresses, Genders. Review…","\u002Fuploads\u002Flogo\u002Fflatearthdave_com.webp",false,{"name":37,"sector":38,"country":39,"website":10,"websiteArchiveUrl":16,"websiteStatus":16,"websiteCheckedAt":20},"Flat Earth Sun, Moon and Zodiac App","Mobile App \u002F Community","United States"]