Hello Cake Data Breach Exposes 23K US Wellness App User Identity Records
HEROIC's DarkHive system discovered the Hello Cake breach, exposing 22,928 records in July 2025. This US-based social and lifestyle platform suffered a database compromise that revealed user email addresses, phone numbers, first and last names, and birthdays belonging to American users of this social app, without exposing any password data.
Why This Is Dangerous
Social app breaches that expose birthdates alongside full names, email addresses, and phone numbers create complete identity profiles that are directly usable for identity theft and account recovery bypass attacks without requiring any password cracking. The combination of birthday, full name, and phone number satisfies the identity verification requirements for many US banking, government, and telecommunications platforms, enabling fraudulent account access through legitimate identity verification channels. Social platform user identity data is particularly valuable for SIM swapping attacks that use confirmed personal details to impersonate victims to mobile carriers.
What Was Exposed
- Email Address
- Phone Number
- First Name
- Last Name
- Birthday
Why This Matters
Hello Cake users whose personal data was exposed face identity theft risk from the combination of birthday, full name, phone number, and email that enables fraudulent account recovery across banking, social media, and government service platforms. SIM swap fraud using confirmed identity details from social app breaches is a growing attack vector that bypasses SMS-based two-factor authentication and can lead to complete account takeover across all platforms tied to a phone number. Anyone whose data was exposed in this breach should monitor their mobile account for unauthorized changes and enable carrier-level SIM swap protections.
How Database Breach Works
Social and lifestyle apps collect rich personal profile data during user registration and ongoing activity, building detailed identity databases that are more comprehensive than basic email and password repositories. Attackers exploit API vulnerabilities and inadequate database access controls in social app backends to extract user profile databases containing verified personal information. The resulting identity data is sold to criminal actors specializing in SIM swapping, identity fraud, and account recovery bypass operations targeting US consumers.
Check If You Are Affected
HEROIC offers a free identity scanner searching over 400 billion records including data from the Hello Cake breach. Visit heroic.com to check if your information was exposed.
Breach Breakdown
22,928 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds