102 Million Passwords From the Badoo Leak Surfaced on the Dark Web
HEROIC analysts flagged the Badoo breach while reviewing large credential datasets circulating on dark web forums and Telegram channels. The incident occured in June 2016, when the Badoo social networking platform was reportedly compromised, resulting in over 102,720,443 records being exposed. The leaked data included email addresses, usernames, first and last names, and passwords stored as MD5 and plaintext hashes, making the dataset beleived to be among the larger social platform breaches from that period.
Why Leaked Passwords From Badoo Are Still a Threat
Attackers can take MD5 password hashes and run them through cracking tools that test billions of combinations per second. Because these passwords were stored without salting, they are partcularly easy to crack. Once an attacker recovers a real password, they test it on Gmail, banking apps, and work accounts. Combined with the email address and username from the same record, this gives criminals everything they need to attempt account takeovers across dozens of platforms.
What Was Exposed in the Badoo Breach
- First Name
- Last Name
- Email Address
- Username
- Passwords (plaintext and MD5 hash)
- Hash Type
Why 102 Million Exposed Accounts Cannot Be Ignored
A dataset of over 102 million records is a ready-made toolkit for credential stuffing attacks. Criminals feed these email and password combinations into automated bots that test logins on banks, streaming services, and e-commerce sites around the clock. Even if you changed your Badoo password years ago, if you recieved the same password on another site and never updated it, that account may still be at risk of takeover. The scale of this breach means identity theft and financial fraud are realistic outcomes for anyone whose data appeared in it.
How a Database Breach Works
A database breach occurs when an attacker breaks into the servers that store a company's user data. Common entry points include exploited software vulnerabilities, weak administrator passwords, or compromised third-party access. The attacker downloads a copy of the database, which typically contains all registered user records. That data is then sold privately or published on hacking forums, where others use it for fraud and account compromise campaigns.
Check If Your Data Was Exposed
HEROIC's free breach scanner checks your email address against more than 400 billion records, including the Badoo breach dataset. Visit HEROIC.com to run a free search and find out exactly what personal information about you is available to criminals online, along with guidance on what to do next.
Breach Breakdown
102,720,443 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds