[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f2pxts09ju3l3v":3},{"success":4,"breach":5},true,{"_id":6,"name":7,"title":8,"slug":7,"domain":9,"breachDate":10,"addedDate":11,"modifiedDate":11,"contentUpdatedAt":12,"source":13,"sourceUrl":14,"sourceUrls":15,"pwnCount":18,"affectedCount":18,"affectedCountStatus":19,"affectedCountLowerBound":20,"affectedCountUnit":21,"hasEnglishDescription":4,"severity":22,"dataClasses":23,"description":27,"seoTitle":28,"seoTitleEn":29,"seoDescription":28,"seoDescriptionEn":30,"logoUrl":31,"isVerified":4,"isSensitive":32,"isSpamList":32,"isMalware":32,"company":33},"68e3266eda11adda4882526f","lifebear","Lifebear Data Breach","lifebear.com","2019-02-28T00:00:00.000Z","2020-05-25T04:02:18.000Z","2026-07-18T23:53:22.681Z","Website breach","https:\u002F\u002Flifebear.com\u002F",[14,16,17],"https:\u002F\u002Fwww.zdnet.com\u002Farticle\u002Fround-4-hacker-returns-and-puts-26mil-user-records-for-sale-on-the-dark-web\u002F","https:\u002F\u002Fwww.scworld.com\u002Fnews\u002Fa-hacker-dubbed-gnosticplayers-and-is-known-for-selling-personal-information-recently-posted-26-42-million-stolen-user-records-for-sale-on-the-dark-web",3670561,"known",null,"unknown","Critical",[24,25,26],"Email addresses","Passwords","Usernames","\u003Cp>The Lifebear data breach is a verified incident from 2019 affecting the Lifebear app, a Japan-based service that provides calendar, ToDo, note, and journal features under a single account. The breach date recorded is confirmed as February 28, 2019, with the number of unique accounts verified as 3,670,561. The dataset contains email addresses, usernames, and password hashes stored in salted MD5 format. This record should not be broadly interpreted as exposing health, financial, phone, physical address, or journal content.\u003C\u002Fp>\n\u003Cp>Since Lifebear is a personal planning tool, account identity can be connected to the services through which users organize their daily lives. Nevertheless, verified data classes are limited. The main risk is targeted phishing via email and username, cracking of salted MD5 password hashes, and trying the same password on other accounts. This incident should be treated as a 2019 breach record; separate claims that appeared on social media in subsequent years should not be considered verified evidence that changes the date or scope of this record.\u003C\u002Fp>\n\u003Ch2>Leaking Data Types and Risks\u003C\u002Fh2>\n\u003Cp>The verified data classes are email addresses, usernames, and passwords. The password field has been verified not as plain text, but as salted MD5 hashes. Using salt makes the attacker's job harder; however, MD5 is an old type of hash that can be tried quickly. Therefore, the risk continues for short, predictable, or reused passwords from other accounts. When email and username are used together, fake account alerts and messaging with a scheduling app theme can become more convincing.\u003C\u002Fp>\n\u003Cul>\u003Cli>\u003Cstrong>Email addresses:\u003C\u002Fstrong> Can be used in messages themed around fake security alerts, account recovery, premium plans, or calendar notifications.\u003C\u002Fli>\u003Cli>\u003Cstrong>Usernames:\u003C\u002Fstrong> May cause the same nickname to match with other applications, forums, or social profiles.\u003C\u002Fli>\u003Cli>\u003Cstrong>Password hashes:\u003C\u002Fstrong> Salted MD5 format is not plain text; still, it carries the risk of trial attempts on weak and repeated passwords.\u003C\u002Fli>\u003Cli>\u003Cstrong>Application context:\u003C\u002Fstrong> Its function as a calendar and diary tool allows attackers to embellish fake notification language with personal planning themes.\u003C\u002Fli>\u003Cli>\u003Cstrong>Risk of incorrect scope:\u003C\u002Fstrong> The dataset should not be described as having leaked calendar notes or diary texts.\u003C\u002Fli>\u003C\u002Ful>\n\u003Ch2>Verified Scope and Boundaries\u003C\u002Fh2>\n\u003Cp>This record should be limited to 3,670,561 unique accounts. The date is verified as February 28, 2019, and the addition date as May 25, 2020. The verified fields are email addresses, usernames, and password hashes. Name-surname, phone, physical address, payment card, note content, diary text, calendar event, task list, or health information are not among the verified data classes of this record.\u003C\u002Fp>\n\u003Cp>The live Lifebear site shows that the service is a Japanese electronic agenda and calendar application. This context can be used in the explanation; however, the scope of the data for the incident is limited to verified account areas only. While some recent social posts may contain different and broader claims, the main event proven for this record is the 2019 Lifebear breach. Security recommendations for users should be provided based on this verified scope.\u003C\u002Fp>\n\u003Ch2>User Groups at Risk\u003C\u002Fh2>\n\u003Cp>The highest risk is for users who reuse the password they use for their Lifebear account on email, social media, work tools, cloud storage, or other productivity applications. Even if an old password is no longer used in the same form today, similar variations may be tried by attackers. The email account is particularly important because recovery links for other services often go there.\u003C\u002Fp>\n\u003Cp>People who actively use Japanese calendar and diary applications may be more susceptible to messages such as fake calendar invitations, paid plan notifications, account lock alerts, or app updates. If the username is also used in different communities, the risk of profile matching increases. Although this does not indicate that the recorded notes and diary content have been leaked, attackers may try to scare the user in this regard to request passwords or payment information.\u003C\u002Fp>\n\u003Ch2>Urgent Measures to Be Taken\u003C\u002Fh2>\n\u003Cp>If your email address matches Lifebear's registration, first identify where else you used that password and similar ones during that period. If the same or derived passwords are still active on accounts, change them immediately. Email accounts, cloud storage, calendar applications, social media, and work tools are priority areas to check. Use a unique and long password for each account.\u003C\u002Fp>\n\u003Col>\u003Cli>\u003Cstrong>Finish repeating the password:\u003C\u002Fstrong> Replace accounts that have the same or similar password as Lifebear with separate passwords.\u003C\u002Fli>\u003Cli>\u003Cstrong>Protect your email account:\u003C\u002Fstrong> Enable multi-factor authentication and check recovery options.\u003C\u002Fli>\u003Cli>\u003Cstrong>Beware of fake calendar messages:\u003C\u002Fstrong> Do not open links containing premium plan, account alert, or calendar invitation from unofficial addresses.\u003C\u002Fli>\u003Cli>\u003Cstrong>Review account sessions:\u003C\u002Fstrong> If there is a notification of a device, region, or login you do not recognize, secure the relevant account.\u003C\u002Fli>\u003Cli>\u003Cstrong>Reduce old app permissions:\u003C\u002Fstrong> Close connected services and old productivity app accounts that you do not use.\u003C\u002Fli>\u003C\u002Fol>\n\u003Ch2>Long-Term Security Strategies\u003C\u002Fh2>\n\u003Cp>Productivity and calendar applications are often closely related to personal life organization. Therefore, not using the main email address for every service, opting for a separate email or masking for important accounts, and using a strong password manager reduce the risk area in the long run. Instead of repeating the same username everywhere, it is healthier to use a separate alias for services that carry high privacy.\u003C\u002Fp>\n\u003Cp>On the platform side, the lesson is clear: fast hash types like MD5 are not sufficient for modern security expectations, even if salt is used. Slow and strong password storage methods, avoiding unnecessary data storage, cleaning up old accounts, and quickly informing users after a breach are basic controls. Users should also keep a regular account inventory to review which email and password they used on which old application.\u003C\u002Fp>\n\u003Ch2>Record Control and User Action\u003C\u002Fh2>\n\u003Cp>Seeing a match in this record indicates that your email address is associated with verified fields in the Lifebear dataset. This result does not mean that your calendar events, notes, journal entries, phone, or physical address were leaked in this incident. Verified scope is limited to email addresses, usernames, and salted MD5 password hashes.\u003C\u002Fp>\n\u003Cp>The most appropriate actions after the check are to remove old password repetitions, protect the email account with multi-factor authentication, be cautious of fake calendar and account alerts, and review old app accounts. Even if you no longer use the Lifebear service, the data set can hold value in the hands of attackers for years. Securing an old planning application account directly strengthens your current email and digital identity security.\u003C\u002Fp>","","Lifebear Data Breach (3.7 Million Reported Records)","Lifebear Data Breach. 3.7 Million reported records were reported. Reported data: Email addresses, Passwords, Usernames. Review the scope, risks, and…","\u002Fuploads\u002Flogo\u002Flifebear_com.webp",false,{"name":34,"sector":35,"country":36,"website":9,"websiteArchiveUrl":28,"websiteStatus":28,"websiteCheckedAt":20},"Lifebear","Calendar & Productivity App","Japan"]