
Fishing app Fishbrain is notifying users of a data breach after an unauthorized person accessed an environment containing user data, exposing personal information and account credentials.
The company says some compromised password hashes may be vulnerable to cracking and has reset affected users’ passwords as a precaution.
According to a breach notification dated September 1, 2026, Fishbrain discovered the unauthorized access on August 19 and immediately launched a forensic investigation. Five days later, on August 24, the company determined that the intruder had accessed information tied to the login credentials of certain users, along with other personal data.
Fishbrain’s investigation indicates the attacker may have accessed the affected environment as early as July 30, meaning the intrusion could have gone undetected for roughly three weeks before being discovered. The company has not disclosed how the attacker initially gained access, how many users are affected, or whether the exposed information has been publicly leaked or misused.
Fishbrain AB is a Stockholm-based company behind the Fishbrain mobile app and online platform, which is designed for anglers to log catches, discover fishing locations, review conditions, and interact with other members of the fishing community. Because the service operates through user accounts, the compromised environment contained both profile information and authentication-related data.
The exposed information included:
- First and last names
- Email addresses
- Telephone numbers
- Fishbrain usernames
- Country information
- Dates of birth
- Password hashes and the corresponding cryptographic salts
Fishbrain stressed that it did not store account passwords in plaintext. However, it warned that the password hashes belonging to some users “may be susceptible to being decoded,” creating a potential risk if attackers can recover the original passwords through offline cracking attacks.
This is particularly concerning for users who reused their Fishbrain password on other websites. Even when a breached service stores passwords as hashes, attackers can attempt to crack weaker passwords and then test recovered credentials against email, social media, shopping, banking, or other online accounts.
Fishbrain says it has patched the vulnerability involved in the incident, restricted access to the affected environment, terminated active sessions for impacted users, and reset their passwords. The company is also conducting a broader security review, strengthening its security controls, and monitoring its systems for additional unauthorized activity.
Affected users should create a new, unique Fishbrain password and immediately change passwords on any other accounts where they reused the same credential. Users should also watch for phishing emails or messages that reference Fishbrain or the breach, especially those requesting passwords, verification codes, or other sensitive information.







Leave a Reply