Dubsmash Data Breach: 149M User Records Exposed (Dec 2018)
149 Million Dubsmash Accounts Exposed in 2018 Data Breach
In December 2018, Dubsmash -- a popular short video messaging app once used by over 100 million people -- suffered a data breach that exposed 149.5 million user records. The compromised data included email addresses, usernames, phone numbers, first and last names, and hashed passwords. The breach wasn't publicaly reported until 2019, when the stolen data appeared for sale on a dark web marketplace as part of a larger package of breached datasets. By then, the stolen records had been accessible to criminal buyers for months.
Dubsmash Data Breach: Breach Summary
- Records Exposed: 149,511,961
- Data Types: Email addresses, usernames, phone numbers, first and last names, password hashes
- Breach Type: Database breach
- Country Affected: United States
- Date Leaked: December 2018
Why the 2019 Dark Web Sale Amplified the Risk
The Dubsmash breach became widely known in early 2019 when the data was packaged and sold on a dark web marketplace alongside records from several other major breaches -- a bundled sale that made the combined credential pool available to a broad audience of criminal buyers. At 149 million records, the Dubsmash portion alone represented one of the largest single-platform breach datasets available at the time. Buyers could cross-reference the Dubsmash emails and password hashes with data from other breached platforms, increasing the liklihood of successful credential stuffing and account takeover attacks acros multiple services where the same credentials were reused.
What Hashed Passwords Mean for Affected Users
The Dubsmash breach exposed password hashes rather than plaintext passwords. Hashing is a one-way cryptographic process -- in theory, a hash can't be reversed. In practice, common passwords and weak hashing algorithms can be cracked through dictionary attacks and rainbow table lookups. Whether a given hash is crackable depends on the algorithm used and the complexity of the original password. For users who had strong, unique passwords, hashing provides meaningfull protection. For users who chose common passwords or reused passwords from other platforms, the hash provides little real defense once attackers have access to the database. Any Dubsmash user who hasn't changed their password since 2018 should treat their credentials as potentialy compromised.
Check if Your Email Appeared in the Dubsmash Breach
HEROIC's free breach scanner searches across more than 400 billion exposed records, including major database breaches like the 2018 Dubsmash incident. Enter your email to see if your credentials have been exposed. If Dubsmash is one of the platforms where you reused a password you still use elsewhere, changing that password now is the most direct step you can take to reduce your risk.
Breach Breakdown
149,511,961 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds