OnlyBaddies Data Breach: Financial and Personal Records Exposed
HEROIC analysts identified a database breach affecting OnlyBaddies, a United States-based adult content platform, with the data surfacing on June 27, 2024. The exposed dataset contained 2,215 user records drawn directly from the platform's user database. What distinguishes this incident from a standard credential dump is the breadth of personal, financial, and behavioral data included in each record. Beyond login credentials, the dataset exposes full identity details, network data, and partial payment card information, creating conditions for financial fraud and identity exploitation well beyond simple account takeover.
Why This Is Dangerous
The combination of sensitive platform category and financial data in a single breach creates compounded risk. Users of adult content platforms face unique exposure: the platform affiliation itself can be used as leverage in extortion or targeted harassment campaigns. Partial credit card data combined with full names, phone numbers, birthdates, and IP addresses gives attackers sufficient material to attempt social engineering against financial institutions or to build convincing fraudulent identities. Bcrypt password hashes, while not directly usable, remain subject to offline cracking attempts and should be treated as compromised.
What Was Exposed
- Email addresses
- Phone numbers
- Password hashes (bcrypt)
- Usernames
- First names and last names
- IP addresses
- Birthdays
- Gender
- Credit card data (partial)
Why This Matters
This breach sits at the intersection of financial fraud, identity theft, and reputational harm. Partial credit card data, when combined with the full names, birthdates, and phone numbers also present in this dataset, provides attackers with material for account takeover attempts against financial institutions. Identity theft risk is elevated by the volume of personally identifying fields. Account takeover via credential stuffing remains a threat even with bcrypt hashes, as weak or commonly used passwords can be recovered through targeted cracking. The sensitive nature of the platform also creates elevated exposure to extortion targeting affected individuals.
How Database Breaches Work
Database breaches occur when an attacker gains unauthorized access to the storage layer of an application, typically through exploiting web application vulnerabilities such as SQL injection, abusing misconfigured cloud storage or database endpoints, or using compromised administrative credentials. Once inside, the attacker exports user tables in bulk. In this case, the breadth of data stored by OnlyBaddies reflects an application that collected extensive personal and financial information, all of which became accessible when the database perimeter was breached. The use of bcrypt for password hashing demonstrates some security awareness, but the unprotected storage of financial and identity data alongside hashed credentials amplified the breach's overall impact significantly.
Check If You Are Affected
HEROIC offers a free identity scanner backed by over 400 billion compromised records. If your email address appeared in the OnlyBaddies database breach or any other known incident, the scanner will identify that exposure. Search your email now at heroic.com and take immediate steps to update passwords, monitor financial accounts, and enable multi-factor authentication on any linked services.
Breach Breakdown
2,215 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds