Jump to content

Under Armour says 150 million MyFitnessPal accounts breached

ItsMitch

Source: https://www.reuters.com/article/us-under-armour-databreach/under-armour-says-150-million-myfitnesspal-accounts-breached-idUSKBN1H532W

Athletic Apparel maker Under Armour has confirmed that 150 million MyFitnessPal accounts have been breached, the data stolen was names, email addresses and "scrambled passwords" (this concerns me as they don't mention if they was fully encrypted or not) 

Excerpt from Reuters

Quote

 

(Reuters) - Under Armour Inc (UAA.N) (UA.N) said on Thursday that data from some 150 million MyFitnessPal diet and fitness app accounts was compromised in February, in one of the biggest hacks in history, sending shares of the athletic apparel maker down 3 percent in after-hours trade.

The stolen data includes account usernames, email addresses and scrambled passwords for the popular MyFitnessPal mobile app and website, Under Armour said in a statement. Social Security numbers, driver license numbers and payment card data were not compromised, it said.

It is the largest data breach this year and one of the top five to date, based on the number of records compromised, according to SecurityScorecard.

 

The firm said that they are working with law enforcement and only decided to inform their users yesterday of the breach (They knew 5 days ago). The company also went on to say they didn't know how exactly the hackers got in and out without triggering any security systems (Makes you wonder how secure it really was) and this is what their official statement was to the press when asked about should customers monitor their accounts.

Quote

“We continue to monitor for suspicious activity and to coordinate with law enforcement authorities,” the company said, adding that it was bolstering systems that detect and prevent unauthorized access to user information.

If you do happen to have an account with Under Armour,  CHANGE YOUR DAMN PASSWORDS

Link to comment
Share on other sites

Link to post
Share on other sites

My wife has an account with them and received an email from them yesterday to make her aware of the situation. So at least the made members aware pretty immediately.

 

Note: They didn't require her SSN. So I don't know what may have been different to cause the need (or lacktherof) for it.

Link to comment
Share on other sites

Link to post
Share on other sites

3 minutes ago, Sierra Fox said:

hang on

 

what the fuck does a fitness app need your SSN for?

That's a er-... that's a good point. No apps in the UK require my NIN (National Insurance Number)

Link to comment
Share on other sites

Link to post
Share on other sites

This implies that people actually use MyFitnessPal? hahaha

Intel Core i7 4790K 4.8GHz | MSI Z97 Gaming 5 | 32GB 2133MHz CL7 DDR3 | nVidia GeForce GTX 1070 with Custom BIOS | Samsung 850 Evo 500GB | 3TB Seagate FireCuda SSHD | 2TB Seagate FireCuda SSHD | Corsair CX750M  | Custom 240mm all-in-one liquid cooler | Broadcom NetXTREME 5709c Dual Gigabit NIC | Cougar MX330 mid-tower chassis | Windows Server 2008 R2 Datacenter

Link to comment
Share on other sites

Link to post
Share on other sites

29 minutes ago, SC2Mitch said:

this concerns me as they don't mention if they was fully encrypted or not

image.png.1d5c27393f4785405cfa07db3532eb05.png

It's seems to be a shoddy encryption :dry:

 

33 minutes ago, SC2Mitch said:

The stolen data includes account usernames, email addresses and scrambled passwords for the popular MyFitnessPal mobile app and website, Under Armour said in a statement. Social Security numbers, driver license numbers and payment card data were not compromised, it said.

It is the largest data breach this year and one of the top five to date, based on the number of records compromised, according to SecurityScorecard.

 

I pity those people who have to include social security numbers and driver's license numbers. I own some Under Armour apparel but I bought them from a physical store. Time to change passwords I guess.

 

2 minutes ago, i_got_laid_by_a_dragoness said:

This implies that people actually use MyFitnessPal? hahaha

I do. It's one of the tools I used to drop 33 pounds of body fat years ago especially when my doctor asked me to limit my caloric intake to just 1800 calories a day.

There is more that meets the eye
I see the soul that is inside

 

 

Link to comment
Share on other sites

Link to post
Share on other sites

3 minutes ago, hey_yo_ said:

It's seems to be a shoddy encryption :dry:

 

HTTPS is fully there.

image.png.b35ee6727dab8e9fc93a7306eb4e7556.png

Link to comment
Share on other sites

Link to post
Share on other sites

42 minutes ago, Sierra Fox said:

hang on

 

what the fuck does a fitness app need your SSN for?

I my issue isn't necessarily why it would ask for your SSN.. But consumers would you give it to a Willy Nilly?

Link to comment
Share on other sites

Link to post
Share on other sites

11 minutes ago, SC2Mitch said:

HTTPS is fully there.

My fitness pal is not encrypted unfortunately :(

myfitnesspal.PNG.e6cfcaf363e6e36a40cd77fb14fe03fb.PNG

There is more that meets the eye
I see the soul that is inside

 

 

Link to comment
Share on other sites

Link to post
Share on other sites

Isn't myfitnesspal also the service that revealed the location of multiple top secret military bases from the US Army?

We have a NEW and GLORIOUSER-ER-ER PSU Tier List Now. (dammit @LukeSavenije stop coming up with new ones)

You can check out the old one that gave joy to so many across the land here

 

Computer having a hard time powering on? Troubleshoot it with this guide. (Currently looking for suggestions to update it into the context of <current year> and make it its own thread)

Computer Specs:

Spoiler

Mathresolvermajig: Intel Xeon E3 1240 (Sandy Bridge i7 equivalent)

Chillinmachine: Noctua NH-C14S
Framepainting-inator: EVGA GTX 1080 Ti SC2 Hybrid

Attachcorethingy: Gigabyte H61M-S2V-B3

Infoholdstick: Corsair 2x4GB DDR3 1333

Computerarmor: Silverstone RL06 "Lookalike"

Rememberdoogle: 1TB HDD + 120GB TR150 + 240 SSD Plus + 1TB MX500

AdditionalPylons: Phanteks AMP! 550W (based on Seasonic GX-550)

Letterpad: Rosewill Apollo 9100 (Cherry MX Red)

Buttonrodent: Razer Viper Mini + Huion H430P drawing Tablet

Auralnterface: Sennheiser HD 6xx

Liquidrectangles: LG 27UK850-W 4K HDR

 

Link to comment
Share on other sites

Link to post
Share on other sites

57 minutes ago, Sierra Fox said:

hang on

 

what the fuck does a fitness app need your SSN for?

 

 

No but seriously joking aside that's a legit wtf moment.

-------

Current Rig

-------

Link to comment
Share on other sites

Link to post
Share on other sites

MyFitnessPal doesn't ask for your SSN or DL number.  That's just a boiler plate statement saying they weren't compromised...because they didn't exist in the first place.

 

Basically the hack doesn't affect me in any way as a user.  My payments were done via the Apple App Store so it's indirect, my email address is probably already in 500 publicly circulating databases, the password I used with it I only use for things that I don't give a shit about (all of my email  and banking and important logins use two factor and unique passwords).

Workstation:  13700k @ 5.5Ghz || Gigabyte Z790 Ultra || MSI Gaming Trio 4090 Shunt || TeamGroup DDR5-7800 @ 7000 || Corsair AX1500i@240V || whole-house loop.

LANRig/GuestGamingBox: 9900nonK || Gigabyte Z390 Master || ASUS TUF 3090 650W shunt || Corsair SF600 || CPU+GPU watercooled 280 rad pull only || whole-house loop.

Server Router (Untangle): 13600k @ Stock || ASRock Z690 ITX || All 10Gbe || 2x8GB 3200 || PicoPSU 150W 24pin + AX1200i on CPU|| whole-house loop

Server Compute/Storage: 10850K @ 5.1Ghz || Gigabyte Z490 Ultra || EVGA FTW3 3090 1000W || LSI 9280i-24 port || 4TB Samsung 860 Evo, 5x10TB Seagate Enterprise Raid 6, 4x8TB Seagate Archive Backup ||  whole-house loop.

Laptop: HP Elitebook 840 G8 (Intel 1185G7) + 3080Ti Thunderbolt Dock, Razer Blade Stealth 13" 2017 (Intel 8550U)

Link to comment
Share on other sites

Link to post
Share on other sites

I received an email from them today about this. I haven't used the app in a couple years and didn't transfer it to my new phone. I changed my password anyway, of course. Shame. Felt like I just dealt with the Imgur breach. 

CPU: i7 9700K GPU: MSI RTX 2080 SUPER VENTUS Motherboard: ASRock Z390 Phantom Gaming 4 RAM: 16GB ADATA XPG GAMMIX D10 3000MHz Storage: ADATA SU630 480GB + Samsung 860 EVO 1TB + Samsung 970 EVO Plus NVMe 1TB + WD Blue 1TB PSU: HighPower 80+ Gold 650W Case: Slate MR Mirror Finish OS: Windows 11 Pro Monitor: Dell S2716DGR 27" Mouse: Logitech G300s Keyboard: Corsair K70 LUX Cherry MX Brown Speakers: Bose Companion 2 Series III Headset: HyperX Cloud Revolver Microphone: Razer Seiren X

Link to comment
Share on other sites

Link to post
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now

×