Back to Blog
critical severity February 01, 2018 · 2 min read

MyFitnessPal — 144 Million Accounts, and Whether Yours Was Safe Depended on When You Joined (2018)

If you have an account with MyFitnessPal, here’s what’s now in circulation.

MyFitnessPal used SHA-1 for older accounts and bcrypt for newer ones. Whether your password survived depends entirely on your signup date — and nobody tells you which side of that line you were on.

One dataset split between a fast hash and a slow one

What happened

In February 2018 the diet and exercise service MyFitnessPal was breached, exposing 143,606,147 unique email addresses alongside usernames and IP addresses. In 2019 the data was listed for sale on a dark-web marketplace among the GnosticPlayers batches and subsequently circulated widely.

Caught in this breach?
You can’t unleak a breach. You can take away what it’s worth.
Deep Sweep shows you every leak tied to you and exactly what to change. Then it strips your name, address and family off the look-up sites that turn a leaked record into somebody knocking on your door — $29 one-time, includes 30 days of Protection. We write to 582 companies. No subscription to start.
Scan free, then Deep Sweep — $29 →
Not ready yet? Run a free breach check on this email
We’ll check it against 13.1B+ leaked records right now — no account needed. Continuous monitoring & alerts are part of Protection.

Two different breaches wearing one name

The password storage is the unusual part and it is genuinely important. MyFitnessPal stored passwords as SHA-1 for earlier accounts and bcrypt for newer ones. The company had migrated its hashing at some point, and the breach caught it mid-transition.

The practical consequence is that this single breach has two completely different risk profiles. If your account predates the migration, your password was protected by a fast hash and should be considered recoverable. If it postdates it, bcrypt almost certainly held.

And here is the part no advice column will tell you: you have no way to find out which group you are in. The migration date was never published, your signup date is not something most people remember, and the dataset does not annotate it. The only safe assumption is the pessimistic one — that yours was SHA-1.

This is exactly the failure mode of a generated breach page that reads DataClasses: Passwords and prints one sentence. The catalogue field is identical for MyFitnessPal and for Wattpad. The correct advice is not.

What a fitness account reveals

The breach itself did not expose weight logs, food diaries or workout history — the exposed classes are email addresses, usernames, IP addresses and passwords. It is worth being precise about that, because inflated claims about health data circulate around this incident.

What the dataset does establish is membership: confirmation that a given person used a weight-management service. That inference alone has been enough to fuel targeted advertising and, in some documented patterns, extortion-flavoured phishing. IP addresses add rough location at the time of use.

The identity-chain implication

Health and fitness accounts are almost always registered with a person's primary personal email address, not a throwaway. People compartmentalise gaming and shopping; they rarely compartmentalise the app they weigh in on.

That makes a fitness-service dataset a high-confidence map from a real, actively used address to a real person — which is precisely the anchor an attacker needs before spending effort on anything else. Under Armour owned MyFitnessPal at the time, and the corporate parent has its own separate entry in the catalogue; the two are distinct incidents and should not be conflated.

What to do now

What You Should Do

  1. Assume SHA-1 unless you know you joined late — you cannot determine which hash protected your account, so plan for the worse one
  2. Change every reuse of that password first; the MyFitnessPal account itself is the least valuable thing at risk
  3. Check the same address against Dubsmash, MyHeritage and Canva, which were sold in the same 2019 batches
  4. Treat emails referencing weight, diet or fitness goals as pretexts built on membership inference, not on leaked health data
  5. Enable 2FA on the email address used, since fitness signups are usually a primary personal address

What the free scan actually returns

Sample resultyou@email.comIllustrative — not a real person

Found on people-search siteswe remove these

These listings are live, public, and legal to remove. That’s what a Deep Sweep buys.

value redacted in this sampleage, relatives, address historySpokeo
value redacted in this samplephone, household, property recordsBeenVerified
value redacted in this sample582 companies checked

Found in breach recordsverifiedreported — unverified

Each record is labeled: confirmed breach data, or an attacker’s claim no one has verified.

verifiedvalue redacted in this samplepassword + phone · 2024telecom breach
unverifiedvalue redacted in this sampleclaimed in ransomware listing · 2026leak-site claim

Leaked data cannot be deleted from the internet — anyone claiming otherwise is lying. Broker listings can be removed. We do the second, and show you exactly what to fix from the first.

Were you a MyFitnessPal customer?
MyFitnessPal is one breach. Your email is probably in others.
143.6M email addresses accounts were exposed here. Check whether yours is one — and find every other leak tied to the same address, in about 15 seconds. No account, no card.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

Report details & sourcing

Severity Critical
Disclosed February 01, 2018
Last reviewed July 22, 2026
Affected 143.6M email addresses
Data exposed Email addressesUsernamesPasswordsIP addresses
Editorial & sourcing policy
GalaxyWarden is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data. Breach information is compiled from publicly accessible sources and threat-intelligence platforms, and is reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — see our content & takedown policy or write to support@galaxywarden.com.
Share this Post on X Reddit Email