Breach Intelligence Report 25 Jul 2022

Our Analysts Found the LifeBear Dump in Private Telegram Channels

HEROIC
HEROIC Threat Intelligence Team
Email Address Username Birthdate Salt Gender Password Hash
Your email may be in this breach. Check in 5 seconds — free, no signup required.
Scan Email →
Records Exposed 3,444,064
Source Type Database
Origin Telegram
Password Type MD5(Salt)

Our analysts found the LifeBear database circulating in private Telegram channels used by credential trading communities in early 2019. The dataset contained 3,444,064 records pulled from the popular Japanese notebook and calendar application, and was attributed to the prolific threat actor known as GnosticPlayers. What made this discovery particularly notable was the presence of application tokens alongside standard credential data, a detail that was largely overlooked in initial reporting. HEROIC analysts beleive these tokens represented a secondary attack vector that could grant account access independent of any password change the user might make.


What Attackers Can Do With App Tokens, Password Hashes and Birthdates

Application tokens are seperate from passwords and are not invalidated when a user resets their login credentials. An attacker holding a valid session token can access a user's account directly through the API, bypassing the login form entirely. When combined with birthdates and email addresses, these tokens can also be used to answer security questions, verify identity on other platforms, and support broader identity theft operations. MD5-salted hashes in this dataset, while more resistant than unsalted MD5, remain crackable with modern GPU-accelerated tools.


What Was Exposed in the LifeBear Breach

  • Email Address
  • Username
  • Birthdate
  • Salt
  • Gender
  • Password Hash

Why a Japanese Calendar App Breach Has Global Security Consequences

LifeBear had millions of users across Japan and internationally at the time of the breach. Personal notebook and productivity apps often hold sensitive data such as schedules, notes, and reminders that users treat as private. The exposure of birthdates, genders, and email addresses from this platform feeds directly into identity theft pipelines. Credential stuffing tools can test the recovered password hashes against dozens of other platforms simultaneously, meaning a single compromised LifeBear account can become the key to unlocking unrelated banking, shopping, or work accounts.


How a Database Breach Works

A database breach involves unauthorized extraction of stored user records from an application's backend systems. In cases tied to the GnosticPlayers group, attackers typically exploited vulnerabilities in web application logic or authentication endpoints to gain database access. Once a connection to the database server was established, complete user tables were exported and then offered for sale or posted publicly. The inclusion of application tokens in the LifeBear breach suggests the attacker had deep enough access to extract session management data alongside core user records.


Check If Your Data Was Exposed

If you used LifeBear before February 2019, your email address, username, birthdate, and password hash may be in the hands of attackers. HEROIC's free breach scanner searches across more than 400 billion compromised records to tell you whether your information appears in this breach or any other known exposure. Check now before your old credentials are used against you.

Breach Breakdown

Domain N/A
Leaked Data Email Address,Username,Birthdate,Salt,Gender,Password Hash
Password Types MD5(Salt)
Date Leaked 25 Jul 2022
Check in 5 seconds

3,444,064 passwords exposed. Is yours one of them?

Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.

All information submitted is Private and Secure. We do not sell or share email addresses. By searching, you agree to HEROIC's Privacy Policy and Terms of Service.

Free forever · No account required · Results in seconds

Private & Secure No Account Needed 3,257 scanned today
Breach Rank #900 by affected users
Impact Score
40
sensitivity + scale + recency
Est. Financial Impact $24.9M fraud, phishing & misuse risk
Scan your email Free →
Scan to sign up

Scan to sign up instantly

24/7 Dark Web Monitoring
Instant Breach Alerts
Secure Data Protection
Your Data is at Risk

Your Personal Information is Exposed

We found your data exposed in multiple breaches. This includes:

  • Email addresses
  • Passwords
  • Phone numbers
  • Financial information
Secure My Information Now

Your information is protected by enterprise-grade security

Your Breach Details

Date:
Severity:
Records Exposed:

Your Exposed Information

Your Risk Level

How This Affects You

Full Breach Details

Premium Insights

Unlock Critical Security Information

Create a free account to access:

  • Full Breach Impact Analysis
  • Identity Theft Risk Score
  • Exposed Credentials Details
  • Personalized Security Recommendations
Create Free Account

Identity Theft Risk Score

Risk Score: 8.7/10 - Critical

Data Exposure Analysis

Passwords Critical
Financial High
Personal Medium
Social High
Security Critical

Breach Timeline Analysis

March 2024 Multiple credentials exposed in recent data breach
January 2024 Password found in dark web marketplace
December 2023 Personal information leaked in major security incident

Security Recommendations

High Priority
Password Security

Critical: Change compromised passwords immediately and enable 2FA on all accounts

Important
Financial Protection

Monitor credit reports and set up fraud alerts with major credit bureaus

Recommended
Identity Protection

Enable advanced identity monitoring and dark web surveillance