Back to Blog
high severity December 01, 2018 · 2 min read

Dubsmash — 162 Million Accounts Sold in a Job Lot (2018)

If you have an account with Dubsmash, here’s what’s now in circulation.

The video-messaging app used PBKDF2, one of the better choices on this list. Its data still ended up on Dream Market in February 2019, in the first of the GnosticPlayers batches — sold beside MyFitnessPal, MyHeritage and a dozen others.

Several breach datasets bundled as one dark-market listing

What happened

In December 2018 the video messaging service Dubsmash lost 161,749,950 unique email addresses along with usernames, names, phone numbers, geographic locations, spoken languages and passwords hashed with PBKDF2.

Caught in this breach?
You can’t unleak a breach. You can take away what it’s worth.
Deep Sweep shows you every leak tied to you and exactly what to change. Then it strips your name, address and family off the look-up sites that turn a leaked record into somebody knocking on your door — $29 one-time, includes 30 days of Protection. We write to 582 companies. No subscription to start.
Scan free, then Deep Sweep — $29 →
Not ready yet? Run a free breach check on this email
We’ll check it against 13.1B+ leaked records right now — no account needed. Continuous monitoring & alerts are part of Protection.

In February 2019 the data appeared for sale on the dark-web marketplace Dream Market, in the first of several batches posted by a seller using the name GnosticPlayers — a listing of roughly 620 million accounts drawn from sixteen sites at once, Dubsmash's 162 million among them. It then circulated more broadly.

PBKDF2 did its job

PBKDF2 is a deliberately slow, salted key-derivation function — the same family of defence as bcrypt. Against it, mass password recovery is impractical, and a reasonable password from a Dubsmash account is very likely still intact.

So on the narrow question most people ask — do I need to change my password? — the honest answer for Dubsmash is: only if you reused it somewhere that stored it badly. That caveat is doing real work, because several of the sites sold in the very same listing did store it badly.

The batch is the risk, not the breach

This is the useful lesson from the GnosticPlayers listings, and it applies to four breaches on this list. Dubsmash, MyFitnessPal, MyHeritage and Canva were all put on sale by the same seller within months of each other. A buyer did not acquire one company's users. They acquired a cross-referenced pool in which the same email address recurs across several sites.

That changes the arithmetic entirely. One breach with strong hashing is a small problem. The same address appearing in four datasets, one of which used weak hashing, means the attacker gets a real password from the weak one and a confirmed account list from the strong ones — and then tries the password against every site in the pool.

Good hashing at Dubsmash protected the Dubsmash password. It did nothing to hide the fact that you had an account there.

The identity-chain implication

Dubsmash's non-password fields are the ones that persist: name, username, phone number, location and spoken language. The app's user base skewed young and creative, and the usernames chosen there frequently became the handles those same people carry on TikTok and Instagram today.

An old short-video-app handle is one of the more reliable ways to link a current creator persona to an account created before that person had any reason to be careful.

What to do now

What You Should Do

  1. Focus on reuse rather than the Dubsmash password itself — PBKDF2 held, so the exposure is your presence in the pool
  2. Check the same email address against MyFitnessPal, MyHeritage and Canva, which were sold in the same batches
  3. Set a carrier port-out PIN, since phone numbers were included
  4. Check whether the Dubsmash username matches a handle you use publicly today
  5. Enable 2FA on any account sharing that email address, because the account list itself is what the buyer purchased

What the free scan actually returns

Sample resultyou@email.comIllustrative — not a real person

Found on people-search siteswe remove these

These listings are live, public, and legal to remove. That’s what a Deep Sweep buys.

value redacted in this sampleage, relatives, address historySpokeo
value redacted in this samplephone, household, property recordsBeenVerified
value redacted in this sample582 companies checked

Found in breach recordsverifiedreported — unverified

Each record is labeled: confirmed breach data, or an attacker’s claim no one has verified.

verifiedvalue redacted in this samplepassword + phone · 2024telecom breach
unverifiedvalue redacted in this sampleclaimed in ransomware listing · 2026leak-site claim

Leaked data cannot be deleted from the internet — anyone claiming otherwise is lying. Broker listings can be removed. We do the second, and show you exactly what to fix from the first.

Were you a Dubsmash customer?
Dubsmash is one breach. Your email is probably in others.
161.7M email addresses accounts were exposed here. Check whether yours is one — and find every other leak tied to the same address, in about 15 seconds. No account, no card.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

Report details & sourcing

Severity High
Disclosed December 01, 2018
Last reviewed July 22, 2026
Affected 161.7M email addresses
Data exposed Email addressesUsernamesNamesPasswordsPhone numbersGeographic locationsSpoken languages
Editorial & sourcing policy
GalaxyWarden is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data. Breach information is compiled from publicly accessible sources and threat-intelligence platforms, and is reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — see our content & takedown policy or write to support@galaxywarden.com.
Share this Post on X Reddit Email