[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f2evz9hsel8z1l":3},{"success":4,"breach":5},true,{"_id":6,"name":7,"title":8,"slug":7,"domain":9,"breachDate":10,"addedDate":11,"publishedAt":12,"modifiedDate":13,"contentUpdatedAt":13,"source":14,"sourceUrl":15,"sourceUrls":16,"pwnCount":17,"affectedCount":17,"affectedCountStatus":18,"affectedCountLowerBound":12,"affectedCountUnit":19,"hasEnglishDescription":4,"contentLocale":20,"availableLocales":21,"translations":23,"severity":26,"dataClasses":27,"description":31,"seoTitle":32,"seoDescription":33,"logoUrl":34,"isVerified":4,"isSensitive":4,"isSpamList":35,"isMalware":35,"company":36},"6a452308a20f867c8ba8e748","quitbro","Quitbro Data Breach","quitbro.app","2026-02-17T00:00:00.000Z","2026-03-02T05:27:11.000Z",null,"2026-07-29T11:40:53.262Z","Third party breach","",[],22874,"known","unknown","en",[20,22],"tr",{"en":24,"tr":25},{"slug":7},{"slug":7},"Medium",[28,29,30],"Email addresses","Partial dates of birth","Usernames","\u003Cp>The Quitbro data breach was recorded in February 2026 as a sensitive incident affecting the user data of a mobile application focused on combating pornography addiction. The dataset, containing approximately 23,000 unique email addresses, included usernames, partial birth date information, and context related to responses to questions within the app. Due to the nature of the application, this record carries a high risk of privacy violations and blackmail, even though the data fields were limited.\u003C\u002Fp> \u003Ch2>Leaked Data Types and Risks\u003C\u002Fh2> \u003Cp>The types of data listed in this record are Email addresses, Partial dates of birth, and Usernames. The password or payment card field is not listed; however, the application context may lead to sensitive inferences about users' personal habits and private life. When combined with this context, email addresses and usernames can make it possible to link a user to their identity across different platforms.\u003C\u002Fp> \u003Ch2>Sensitive Application Context and Risk of Blackmail\u003C\u002Fh2> \u003Cp>The most important risk in Quitbro registration is not account hijacking, but the misuse of privacy. An attacker may claim that the user is associated with such an application and send messages for blackmail, embarrassment, fake support, or account closure. These messages may request urgent payments, sharing of additional information, or clicking a link. Users should not act in panic and should keep the messages as evidence.\u003C\u002Fp> \u003Cp>The partial dates of birth field may not be as detailed as the full date of birth; however, when combined with email and username, it increases the risk of identity matching. If the same username is used on social media, forums, health apps, or community accounts, an attacker can build a broader profile from different sources. Using a unique username and separate email address for services in sensitive contexts reduces this risk.\u003C\u002Fp> \u003Ch2>The Privacy Impact of In-App Responses\u003C\u002Fh2> \u003Cp>Although the responses to in-app questions may not be individually listed in the data class list, they are important in terms of event context. Information such as dependency, personal struggle, relapse timing, or behavior tracking can be highly personal for the user. Misuse of such data should be considered not only from a technical security perspective but also in terms of personal safety and psychological pressure.\u003C\u002Fp> \u003Ch2>Necessary Precautions\u003C\u002Fh2> \u003Cp>Even if the password field is not listed, affected users need to protect their email accounts. The primary email account is the recovery point for other services, and extortion or fake support messages can come through this account. Multi-factor authentication should be enabled, session history should be checked, and personal information should be reduced on public profiles under the same username.\u003C\u002Fp> \u003Ch2>Data Minimization for Organizations\u003C\u002Fh2> \u003Cp>From an organizational perspective, the Quitbro incident demonstrates that applications involving sensitive health, habit, or personal development contexts need to pay particular attention to data minimization. Even basic fields like email and username can become sensitive data when combined with the purpose of the application. Therefore, account deletion, data downloading, limited retention, strong access control, and notifying the user in a calm manner are of critical importance.\u003C\u002Fp> \u003Cp>Affected users should carefully examine account closure, support, payment, data deletion, identity verification, or threat-related messages coming under the name Quitbro. Verification codes, passwords, or additional personal information should not be shared in any message. In the event of a leak in a sensitive context, the healthiest approach is to split digital identity, strengthen the email account, and contact trusted support channels without responding to messages that contain pressure.\u003C\u002Fp> \u003Ch2>Long-Term Privacy and Support Risk\u003C\u002Fh2> \u003Cp>The Quitbro record shows how important the expectation of anonymity is for users in sensitive support and habit-tracking applications. In such applications, the user does not just create a technical account; most of the time, they share a personal struggle, behavior history, or personal goal. Therefore, fields that seem simple, such as email and username, become a strong signal about a person's private life when combined with the context of the application.\u003C\u002Fp> \u003Cp>Affected users should not try to deal with pressure or threat messages directed at them on their own. If there is blackmail, a threat of exposure, or a demand for payment, the messages should be kept without being deleted, and help should be sought from a trusted person or an appropriate support channel. Alongside digital security measures, psychological safety is also important; messages that force urgent decisions should be considered signs of fraud.\u003C\u002Fp>","Quitbro Data Breach (22.9 Thousand Reported Records)","Quitbro Data Breach. 22.9 Thousand reported records are reported. Reported data: Email addresses, Partial dates of birth, Usernames. Review the scope, risks…","\u002Fuploads\u002Flogo\u002Fquitbro_app.webp",false,{"name":37,"sector":38,"country":15,"website":9,"websiteArchiveUrl":39,"websiteStatus":40,"websiteCheckedAt":41},"Quitbro","Health App","https:\u002F\u002Fweb.archive.org\u002Fweb\u002F20250816205052\u002Fhttps:\u002F\u002Fquitbro.app\u002F","archived","2026-07-29T11:30:22.391Z"]