Wishbone hack - data of 40 million users up for sale

(Image credit: Pixabay)

A database of 40 million users of the popular Wishbone application has been put for sale on the dark web.

ZDNet discovered Wishbone user accounts were available on underground forums for 0.85 bitcoin - currently around $8000. The popular mobile app allows users to compare two or more items in voting polls.

The hacking attempt appears to have taken place earlier this year, with the criminals able to get access to details including usernames, emails, phone numbers, city/state/country and hashed passwords.

Since Wishbone is popular among children, the presence of personally identifiable details like profile pictures and profiles URLs may pose a serious threat to their safety.

Wishbone hack

In a prepared statement, Mammoth Media, the parent company of Wishbone, stated, "Protecting data is of the utmost importance. We are investigating this matter and will share any significant developments.”

According to the report, the passwords were not encrypted properly and were stored in a weak MD5 hashing format. Unlike SHA1 hashing, passwords stored in MD5 format can be easily cracked with the help of various tools freely available on the Internet. 

Experts believe the poster may be a reseller or a broker who is looking to make money by reselling the data. Apart from Wishbone, the hacker has also put databases of other companies up for sale, with over 1.5 billion records available, many of which from companies which reported a data breach in the recent past. 

Wishbone was previously attacked in 2017, when hackers were able to steal the data of over 2.2 million users. However, the sample data shared by the hacker in this instance did not match any listed online, seemingly confirming this is a new hack.

Via: ZDNet

Jitendra Soni

Jitendra has been working in the Internet Industry for the last 7 years now and has written about a wide range of topics including gadgets, smartphones, reviews, games, software, apps, deep tech, AI, and consumer electronics.  

Latest in Security
Hacker silhouette working on a laptop with North Korean flag on the background
North Korea unveils new military unit targeting AI attacks
An image of network security icons for a network encircling a digital blue earth.
US government warns agencies to make sure their backups are safe from NAKIVO security issue
Laptop computer displaying logo of WordPress, a free and open-source content management system (CMS)
This top WordPress plugin could be hiding a worrying security flaw, so be on your guard
Computer Hacked, System Error, Virus, Cyber attack, Malware Concept. Danger Symbol
Veeam urges users to patch security issues which could allow backup hacks
UK Prime Minister Sir Kier Starmer
The UK releases timeline for migration to post-quantum cryptography
Representational image depecting cybersecurity protection
Cisco smart licensing system sees critical security flaws exploited
Latest in News
Ray-Ban Meta Smart Glasses
Samsung's rumored smart specs may be launching before the end of 2025
Apple iPhone 16 Review
The latest iPhone 18 leak hints at a major chipset upgrade for all four models
Quordle on a smartphone held in a hand
Quordle hints and answers for Monday, March 24 (game #1155)
NYT Strands homescreen on a mobile phone screen, on a light blue background
NYT Strands hints and answers for Monday, March 24 (game #386)
NYT Connections homescreen on a phone, on a purple background
NYT Connections hints and answers for Monday, March 24 (game #652)
Quordle on a smartphone held in a hand
Quordle hints and answers for Sunday, March 23 (game #1154)