Dubsmash — 162 Million Accounts Sold in a Job Lot (2018)
If you have an account with Dubsmash, here’s what’s now in circulation.
The video-messaging app used PBKDF2, one of the better choices on this list. Its data still ended up on Dream Market in February 2019, in the first of the GnosticPlayers batches — sold beside MyFitnessPal, MyHeritage and a dozen others.
What happened
In December 2018 the video messaging service Dubsmash lost 161,749,950 unique email addresses along with usernames, names, phone numbers, geographic locations, spoken languages and passwords hashed with PBKDF2.
In February 2019 the data appeared for sale on the dark-web marketplace Dream Market, in the first of several batches posted by a seller using the name GnosticPlayers — a listing of roughly 620 million accounts drawn from sixteen sites at once, Dubsmash's 162 million among them. It then circulated more broadly.
PBKDF2 did its job
PBKDF2 is a deliberately slow, salted key-derivation function — the same family of defence as bcrypt. Against it, mass password recovery is impractical, and a reasonable password from a Dubsmash account is very likely still intact.
So on the narrow question most people ask — do I need to change my password? — the honest answer for Dubsmash is: only if you reused it somewhere that stored it badly. That caveat is doing real work, because several of the sites sold in the very same listing did store it badly.
The batch is the risk, not the breach
This is the useful lesson from the GnosticPlayers listings, and it applies to four breaches on this list. Dubsmash, MyFitnessPal, MyHeritage and Canva were all put on sale by the same seller within months of each other. A buyer did not acquire one company's users. They acquired a cross-referenced pool in which the same email address recurs across several sites.
That changes the arithmetic entirely. One breach with strong hashing is a small problem. The same address appearing in four datasets, one of which used weak hashing, means the attacker gets a real password from the weak one and a confirmed account list from the strong ones — and then tries the password against every site in the pool.
Good hashing at Dubsmash protected the Dubsmash password. It did nothing to hide the fact that you had an account there.
The identity-chain implication
Dubsmash's non-password fields are the ones that persist: name, username, phone number, location and spoken language. The app's user base skewed young and creative, and the usernames chosen there frequently became the handles those same people carry on TikTok and Instagram today.
An old short-video-app handle is one of the more reliable ways to link a current creator persona to an account created before that person had any reason to be careful.
What to do now
What You Should Do
- Focus on reuse rather than the Dubsmash password itself — PBKDF2 held, so the exposure is your presence in the pool
- Check the same email address against MyFitnessPal, MyHeritage and Canva, which were sold in the same batches
- Set a carrier port-out PIN, since phone numbers were included
- Check whether the Dubsmash username matches a handle you use publicly today
- Enable 2FA on any account sharing that email address, because the account list itself is what the buyer purchased
What the free scan actually returns
Found on people-search siteswe remove these
These listings are live, public, and legal to remove. That’s what a Deep Sweep buys.
Found in breach recordsverifiedreported — unverified
Each record is labeled: confirmed breach data, or an attacker’s claim no one has verified.
Leaked data cannot be deleted from the internet — anyone claiming otherwise is lying. Broker listings can be removed. We do the second, and show you exactly what to fix from the first.
Report details & sourcing
Related breaches
How 2026's Credential Mega-Dumps Fuel Account Takeovers — Analysis
2026 has already seen multiple 100M+ credential mega-dumps. Most are infostealer log compilations th…
Wattpad — 268 Million Records, and the Passwords Were the Least of It (2020)
Wattpad hashed its passwords with bcrypt, which held up. The problem is the other eleven fields: bio…
MyFitnessPal — 144 Million Accounts, and Whether Yours Was Safe Depended on When You Joined (2018)
MyFitnessPal used SHA-1 for older accounts and bcrypt for newer ones. Whether your password survived…