Cybersecurity

MyFitnessPal Breach Revisited: How 150 Million Accounts Exposed a Massive Security Gap

December 14, 20253 min read

When Under Armour’s MyFitnessPal platform suffered a data breach in 2018, the fitness world barely had time to catch its breath. In one swift move, attackers accessed 150 million user accounts, turning one of the world’s most popular wellness apps into a cautionary tale of what happens when large-scale platforms underestimate evolving cyber risk.

Even years later, the breach remains a benchmark in cybersecurity history—a reminder that user trust can evaporate in seconds when encryption, access controls, and vulnerability management lag behind.


⚠️ What Actually Happened

The breach struck in February 2018, and Under Armour publicly disclosed it on March 29, 2018—a refreshingly prompt notification compared to many enterprises today.

Threat actors infiltrated MyFitnessPal’s user database and exfiltrated:

  • Usernames

  • Email addresses

  • Hashed passwords (bcrypt for some, weaker SHA-1 for others)

No credit card information or government-issued IDs were involved, but the compromise’s scale alone made this a cybersecurity wake-up call for consumers and corporations alike.

Despite extensive analysis, no threat group ever claimed responsibility, leaving the incident shrouded in mystery.


🧩 How the Attack Worked

Attackers exploited weaknesses within the MyFitnessPal database and accessed stored credentials. The real issue wasn’t just the intrusion—it was the inconsistent hashing practices:

  • bcrypt: Strong, modern hashing algorithm

  • SHA-1: Outdated and vulnerable to brute-force attacks

When attackers discover legacy encryption in a platform handling sensitive data, it’s like leaving a modern vault secured by a rusty padlock.


🕒 MyFitnessPal Breach Timeline

February 2018 — Attackers breach the database
March 29, 2018 — Under Armour discloses the breach
Post-disclosure — Users forced to reset passwords and secure linked accounts

Under Armour immediately launched a forensic investigation, updated encryption, and tightened security controls. But the damage—trust, reputation, and user confidence—was already done.


📉 What Data Was Stolen?

The payload included:

  • Usernames

  • Email addresses

  • Hashed passwords (bcrypt + SHA-1 mix)

Not stolen:

  • Credit cards

  • SSNs

  • Payment information

Even so, attackers gained enough personal information to fuel password-reuse attacks, phishing campaigns, and identity-targeted social engineering.


📊 Who Was Impacted?

Anyone with a MyFitnessPal account created before February 2018 was potentially compromised.

At 150 million users, this remains one of the largest breaches in consumer app history.


🔍 Key Lessons for Businesses

MyFitnessPal’s breach still resonates because it exposed a universal truth:

Cybersecurity failures usually aren’t exotic—they’re preventable.

Enterprises today should take note:

🔐 1. Use modern encryption everywhere

Legacy hashing algorithms like SHA-1 have no place in modern security architectures.

🩹 2. Patch aggressively

Old vulnerabilities become the easiest entry points.

👤 3. Require strong, unique passwords + MFA

User hygiene remains as crucial as technical controls.

🛡 4. Train, test, repeat

Phishing and credential theft remain the #1 attack vectors—education is a defensive superpower.


🏁 Is Under Armour Secure Today?

Under Armour has significantly strengthened its security posture since the incident:

  • Stronger data encryption

  • Improved incident response

  • Audits and infrastructure hardening

Still, no system is breach-proof—and MyFitnessPal remains proof that even household brands can fall when gaps go unchecked.


🛠 How Users Can Protect Themselves

  • Enable Multi-Factor Authentication

  • Use unique, complex passwords

  • Monitor accounts for suspicious activity

  • Be cautious of phishing emails referencing old breaches


🧠 Final Thought

The MyFitnessPal breach wasn’t just a cybersecurity failure—it was a turning point.
It reminded the world that massive platforms carry massive responsibility, and that poor encryption hygiene can trigger global-scale compromise.

At Elliptic Systems, we help organizations stay ahead of incidents like this through:


AI-driven risk assessments
Penetration testing
Zero Trust architecture
Incident response planning
Compliance + governance


Because the next breach doesn’t need to be inevitable.

Eric Stefanik

Eric Stefanik

Ai Consultant | Best-selling Author | Speaker | Innovator | Leading Cybersecurity Expert

LinkedIn logo icon
Instagram logo icon
Youtube logo icon
Back to Blog