Our Analysts Found the LifeBear Dump in Private Telegram Channels
Our analysts found the LifeBear database circulating in private Telegram channels used by credential trading communities in early 2019. The dataset contained 3,444,064 records pulled from the popular Japanese notebook and calendar application, and was attributed to the prolific threat actor known as GnosticPlayers. What made this discovery particularly notable was the presence of application tokens alongside standard credential data, a detail that was largely overlooked in initial reporting. HEROIC analysts beleive these tokens represented a secondary attack vector that could grant account access independent of any password change the user might make.
What Attackers Can Do With App Tokens, Password Hashes and Birthdates
Application tokens are seperate from passwords and are not invalidated when a user resets their login credentials. An attacker holding a valid session token can access a user's account directly through the API, bypassing the login form entirely. When combined with birthdates and email addresses, these tokens can also be used to answer security questions, verify identity on other platforms, and support broader identity theft operations. MD5-salted hashes in this dataset, while more resistant than unsalted MD5, remain crackable with modern GPU-accelerated tools.
What Was Exposed in the LifeBear Breach
- Email Address
- Username
- Birthdate
- Salt
- Gender
- Password Hash
Why a Japanese Calendar App Breach Has Global Security Consequences
LifeBear had millions of users across Japan and internationally at the time of the breach. Personal notebook and productivity apps often hold sensitive data such as schedules, notes, and reminders that users treat as private. The exposure of birthdates, genders, and email addresses from this platform feeds directly into identity theft pipelines. Credential stuffing tools can test the recovered password hashes against dozens of other platforms simultaneously, meaning a single compromised LifeBear account can become the key to unlocking unrelated banking, shopping, or work accounts.
How a Database Breach Works
A database breach involves unauthorized extraction of stored user records from an application's backend systems. In cases tied to the GnosticPlayers group, attackers typically exploited vulnerabilities in web application logic or authentication endpoints to gain database access. Once a connection to the database server was established, complete user tables were exported and then offered for sale or posted publicly. The inclusion of application tokens in the LifeBear breach suggests the attacker had deep enough access to extract session management data alongside core user records.
Check If Your Data Was Exposed
If you used LifeBear before February 2019, your email address, username, birthdate, and password hash may be in the hands of attackers. HEROIC's free breach scanner searches across more than 400 billion compromised records to tell you whether your information appears in this breach or any other known exposure. Check now before your old credentials are used against you.
Breach Breakdown
3,444,064 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds