[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$flc8an96pfk2b":3},{"success":4,"breach":5},true,{"_id":6,"name":7,"title":8,"slug":9,"domain":10,"breachDate":11,"addedDate":12,"modifiedDate":12,"contentUpdatedAt":13,"source":14,"sourceUrl":15,"sourceUrls":16,"pwnCount":17,"affectedCount":17,"affectedCountStatus":18,"affectedCountLowerBound":19,"affectedCountUnit":20,"hasEnglishDescription":4,"severity":21,"dataClasses":22,"description":28,"seoTitle":29,"seoTitleEn":30,"seoDescription":29,"seoDescriptionEn":31,"logoUrl":32,"isVerified":4,"isSensitive":4,"isSpamList":33,"isMalware":33,"company":34},"68e3266eda11adda488252c7","mobi-friends","MobiFriends Data Breach","mobifriends","mobifriends.com","2020-01-06T00:00:00.000Z","2021-05-23T03:16:52.000Z","2026-07-18T23:54:44.638Z","Dating app breach","https:\u002F\u002Fwww.zdnet.com\u002Farticle\u002Fdating-app-mobifriends-silent-on-security-breach-impacting-3-6-million-users\u002F",[15],3512952,"known",null,"unknown","Critical",[23,24,25,26,27],"Dates of birth","Email addresses","Genders","Passwords","Usernames","\u003Cp>The MobiFriends data breach concerns user data exposed in January 2020 on the Barcelona-based dating application mobifriends.com. The verified record contains 3,512,952 unique email addresses. The dataset includes birth dates, email addresses, genders, passwords, and usernames. The password field was reported as MD5 hashes; this storage method is considered weak by modern standards, posing a serious risk for people who reuse passwords. Due to the dating app context, the incident should be considered sensitive not only in terms of account security but also in terms of privacy, profile matching, and targeted social engineering.\u003C\u002Fp>\n\u003Ch2>Leaking Data Types and Risks\u003C\u002Fh2>\n\u003Cp>In this incident, the verified data classes are birth dates, email addresses, genders, passwords, and usernames. Phone numbers, physical addresses, payment cards, private message contents, or exact location information are not among the verified fields for this record. When email and username are found together, the risk of matching with different social accounts increases. Gender and birth date provide additional information about the user profile in the context of a dating application. MD5 password hashes increase the risk of being cracked or tried on other services for individuals using weak passwords.\u003C\u002Fp>\n\u003Cp>Dating app data holds special importance in terms of privacy. Even if the user opened this account a long time ago, the combination of email address, username, gender, and date of birth can help identify the person. Attackers may reach the user using themes such as fake dating messages, account security alerts, profile verification, or old account closure. The presence of password hashes further increases the risk if the same password or a similar password pattern is used on other accounts. Therefore, registration requires caution both for account security and personal privacy.\u003C\u002Fp>\n\u003Ch2>Verified Scope and Boundaries\u003C\u002Fh2>\n\u003Cp>The verified event date is taken as January 6, 2020, and the record addition and source change date as May 23, 2021. The number of unique emails is 3,512,952. Data classes are limited to date of birth, email address, gender, password, and username. The password field should be understood as MD5 hashes. For this record, phone number, physical address, payment information, private message, photo, real-time location, or identity document are not among the verified data classes.\u003C\u002Fp>\n\u003Cp>Correct reading of the scope is important for the recommendations to be given to the user. A positive match does not prove that all of the user's dating profile content or private messages are present in this dataset. Nevertheless, date of birth, gender, username, email, and password hashes together create a sufficiently sensitive profile. The use of the application for dating purposes has a higher privacy impact compared to an ordinary forum account. Therefore, the registration should be marked as sensitive data, and recommendations should be given to the user regarding both password and profile privacy.\u003C\u002Fp>\n\u003Ch2>User Groups at Risk\u003C\u002Fh2>\n\u003Cp>The highest risk group consists of people who have opened an account on MobiFriends and used the same email address on other dating or social media accounts. Those who use the same username across different platforms carry a higher risk in terms of profile matching. Date of birth and gender fields may contribute to fake messages appearing personalized. Users who have forgotten their old accounts are also at risk, because password patterns used years ago may have been continued on other services.\u003C\u002Fp>\n\u003Cp>People who reuse passwords carry additional risk. Since MD5 hashes are not considered strong, weak passwords can be guessed more easily. If the user has used the same password on email, social media, messaging, shopping, or financial accounts, a previous MobiFriends breach could affect the security of current accounts. The dating app context can also be used for embarrassment, fake romantic communication, account takeover threats, or messages requesting personal information. Therefore, the person experiencing a positive match should check not only the password but also communication privacy and social profile visibility.\u003C\u002Fp>\n\u003Ch2>Urgent Measures to Be Taken\u003C\u002Fh2>\n\u003Cp>The user who finds a match in this record should now consider the password they may have used on their MobiFriends account as unreliable. If the same or a similar password exists on other services, a unique password should be chosen for each account. Priority should be given to email accounts, social media, messaging, dating apps, and payment-linked accounts. Multi-factor authentication should be enabled on supported accounts, active sessions should be closed, and recovery information should be checked. It is not sufficient to maintain the old password with minor changes.\u003C\u002Fp>\n\u003Cp>Caution should be exercised with messages themed around dating apps or old accounts. Messages containing real email, username, date of birth, or gender information should not be considered reliable. Links in messages such as profile verification, account closure, match notification, security alert, or private photo threat should not be clicked; verification should be done by manually typing the known address of the service. No payment should be sent, verification codes should not be shared, and personal information should not be given in suspicious messages.\u003C\u002Fp>\n\u003Ch2>Long-Term Security Strategies\u003C\u002Fh2>\n\u003Cp>In the long term, using a separate email from the main account for dating and social apps reduces privacy risks. Using the same username on every platform might be convenient, but it increases the risk of profile matching. Users should periodically review old dating accounts, reduce visible information on profiles they no longer use, and close the account if possible. Fields like birth date, gender, and username may seem minor, but when combined with different datasets, they can help identify a person.\u003C\u002Fp>\n\u003Cp>Password security requires a permanent habit. Using a password manager facilitates generating unique passwords for each dating and social account. Multi-factor authentication should remain enabled on the email account, recovery channels should be kept up to date, and unexpected login alerts should be considered. Dating app breaches can impact privacy independently of financial data. Therefore, the security strategy should not be limited to changing the password; profile visibility, social media connections, and communication channels should also be regularly reviewed.\u003C\u002Fp>\n\u003Ch2>Record Control and User Action\u003C\u002Fh2>\n\u003Cp>A match seen in this record indicates that the email address is among the verified addresses in the MobiFriends dataset. The match does not prove that the phone number, physical address, payment card, private message, or photo is included in this dataset. The verified fields are date of birth, email address, gender, MD5 password hashes, and usernames. By correctly reading this limit, the user should both stop reusing passwords and assess the privacy risk in the context of the dating application.\u003C\u002Fp>\n\u003Cp>The first step is to identify accounts that use the same email and similar password patterns. Then, unique passwords should be adopted for email, social media, dating apps, and messaging accounts, multi-factor authentication should be enabled, and active sessions should be checked. Old dating account messages themed around profile verification or security alerts should be verified through a separate channel. This record presents verified data fields without exaggeration and provides actionable measures to the user for password security, profile privacy, and social engineering risks.\u003C\u002Fp>","","MobiFriends Data Breach (3.5 Million Reported Records)","MobiFriends Data Breach. 3.5 Million reported records were reported. Reported data: Dates of birth, Email addresses, Genders. Review the scope, risks, and…","\u002Fuploads\u002Flogo\u002Fmobifriends_com.webp",false,{"name":35,"sector":36,"country":37,"website":10,"websiteArchiveUrl":29,"websiteStatus":29,"websiteCheckedAt":19},"MobiFriends","Dating App \u002F Social Discovery","Spain"]