CSIDB logo
Incident

Plenty of Fish

Incident posture

Attack window
Dec 2020
Location
United States of America
Status
Historical
CIA posture
Available to members
Updated
2026-09-03 11:55

Linked entities

Victim
Plenty of Fish
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Dec 2020
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

A threat actor operating through a data breach broker listed stolen user records from twenty-six companies for sale on a hacker forum, totaling roughly 368.8 million records. The combined offering included previously disclosed breaches as well as newly advertised datasets, with pricing examples ranging from approximately $1,800 to $4,000 for individual company databases. Among the affected organizations was the dating platform Plenty of Fish, appearing under its legacy Singlesnet.com domain with 16 million user records tied to the previously known breach. The broker marketed the aggregated collection to other criminals on the forum, exposing account credentials and other personal information across the affected services. The incident underscored the recurring pattern of brokers repackaging and reselling stolen data originally obtained in separate intrusions.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

2 techniques

Description

In late December 2020, a data breach broker initiated the sale of approximately 368.8 million stolen user records on a hacker forum, presenting the aggregated data as having been taken from twenty-six different companies. BleepingComputer reported that the broker began marketing the combined dataset the previous Friday, and that of the twenty-six companies listed, only eight had not previously been publicly associated with a data breach. The article enumerated these previously undisclosed alleged victims as Teespring.com, MyON.com, Chqbook.com, Anyvan.com, Eventials.com, Wahoofitness.com, Sitepoint.com, and ClickIndia.com. The remaining eighteen companies included in the sale had been previously disclosed in earlier data breach reporting or were linked to known prior incidents. The article listed pricing information for some of the newly alleged breaches, with Teespring offered at between $3,800 and $4,000, MyON at $2,800, and Chqbook at $1,800, while the broker had not yet established pricing for the other databases.

Among the previously disclosed companies whose records appeared in the broker's listing were Juspay.in (100 million records), Netlog.com/Twoo.com (53 million), Pizap.com (60 million), Fotolog.com (33 million), Bigbasket.com (20 million), Singlesnet.com (16 million), MyON.com (13 million), Teespring.com (8.2 million), ClickIndia.com (8 million), Reverbnation.com (7.8 million), Geekie.com.br (8.1 million), Knockcrm.com (6 million), Reddoorz.com (5.8 million), Wongnai.com (4.3 million), Anyvan.com (4.1 million), Hybris.com/SAP.com (4 million), Everything5pounds.com (2.9 million), Cermati.com (2.9 million), Accuradio.com (2.2 million), Mindful.org (1.7 million), Wahoofitness.com (1.7 million), Eventials.com (1.4 million), Wedmegood.com (1.3 million), ModaOperandi.com (1.2 million), Chqbook.com (1 million), and Sitepoint.com (1 million). The full table in the article documented the user record counts and marked each entry as either previously known or newly alleged.

Following publication of the forum listing, BleepingComputer contacted the companies that had not previously disclosed breaches. MyON responded that its systems had indeed been breached but maintained that no confidential student or customer data had been compromised, stating that it became aware of the bad actor attempting to sell portions of its data on the dark web in July 2020 and had since instituted supplemental protections in addition to its standard information security measures. Samples of the MyON data observed by BleepingComputer showed login names, BCrypt hashed passwords, and names. Chqbook, in contrast, denied any breach, asserting that there had been no data breach and that no customer information had been compromised, and stating that data security was a key priority area and that periodic security audits were conducted. BleepingComputer indicated it was independently verifying the Chqbook data by emailing users listed in the sample.

Regarding Teespring, BleepingComputer first contacted the company on December 27 after learning of the breach and was initially told that the incident was being investigated. Subsequent follow-up emails were not answered. It was later determined that Teespring had already published a data breach notification on December 1, though the advisory included a noindex HTML tag that prevented search engines from indexing it. Reports of phishing emails targeting Teespring users' mailboxes were also received. BleepingComputer noted that it could not confirm whether the stolen Teespring data had been used maliciously. Aside from the responses from MyON and Chqbook, the article stated that it had not yet been confirmed whether the remaining six previously undisclosed companies had suffered data breaches, though historically sold data breaches of this nature tended to be legitimate and companies often disclosed them once the information became public. BleepingComputer advised users of the listed sites to change their passwords to strong, unique ones used only at those sites, and to update any reused passwords elsewhere, recommending the use of a password manager. An update dated January 22, 2020, added further information regarding the Teespring data breach notification.

Sources

Sources available to members: 1 source.

CSIDB