Data breach
Aptoide
- Records
- 19,997,507
- Breach date
- 13 April 2020Estimated
- Added
- 1 December 2024
What was exposed
3 types of data · 2 more reported
- IP addresses19,997,506
- Names19,996,748
- Email addresses19,995,926
- PasswordsReported, not counted
- Dates of birthReported, not counted
Reported in the breach write-up; not counted in the analysed data.
About this breach
In April 2020, a hacker leaked details from roughly 20 million user accounts belonging to Aptoide, an independent Android app store, on a well-known hacking forum. The attacker claimed to have breached the platform earlier that month and to hold a larger trove of about 39 million user records, according to reporting by ZDNet that was later covered by SecurityAffairs and Android Police. The leaked records covered people who registered on or used the Aptoide app between July 21, 2016 and January 28, 2018.
The indexed dataset associated with this listing contains just under 20 million rows, with IP addresses, email addresses, and names found across the records. The team estimates the attack date as April 13, 2020, and the listing was added to the index on December 1, 2024. No claiming actor is recorded.
Breach Timeline
April 17, 2020: The breach first surfaced publicly when the monitoring service Under the Breach reported it on Twitter, saying roughly 39 million accounts had been copied and 20 million leaked as proof, per Android Police.
April 21, 2020: Aptoide published a statement on its blog and temporarily disabled all account-based activity, including sign-ups, logins, reviews, and comments, while it investigated, per Android Authority.
What Information Was Compromised?
Our analysis found the following data types in this breach: IP addresses, email addresses, and names.
Beyond those fields, contemporaneous reporting on the leaked dump described additional content, including SHA-1 hashed passwords, registration dates, device details, dates of birth where users had added them, account status, sign-up tokens, developer tokens, and referral origin, per SecurityAffairs. Aptoide itself said the passwords for email-registered accounts were encrypted, while security reporters noted that unsalted SHA-1 hashing is no longer considered a secure method, per Android Police.
Not every individual is affected by every type of data listed here.
What Are the Potential Risks for Affected Individuals?
The most immediate risk involves passwords. Anyone who reused an Aptoide password on other accounts could face credential stuffing, where attackers try leaked email and password pairs against other services. Although the passwords were hashed, weak passwords can be recovered through brute-force attacks, a possibility Aptoide itself acknowledged in its statement, per Android Authority.
Exposed email addresses and names also enable targeted phishing. Attackers can send convincing messages that reference the app store or impersonate its support team, hoping recipients will hand over credentials or payment details. IP addresses and device details add a smaller layer of exposure, giving scammers technical details that can make fraudulent messages appear more legitimate.
What Is Aptoide Doing in Response?
Aptoide confirmed the incident in a blog post. The company said it was working with its data center partners to determine how the intrusion happened, and it temporarily disabled registrations, logins, reviews, and comments while keeping app downloads and updates functional, according to Android Police. The company said users would be required to set a new password at their next login, and it noted that roughly 32 million of the affected accounts used Google or Facebook sign-in and had no passwords stored in the leaked database.
What Should You Do If You Were Affected?
Change your Aptoide password, and change it anywhere else you used the same one.
Use a unique, strong password for each account, ideally with a password manager.
Turn on two-factor authentication wherever the service offers it.
Watch your inbox for phishing emails that reference Aptoide or ask you to log in through a link, and avoid clicking links in unexpected messages.
In the news
- SecurityAffairs: Hacker claims to have stolen 39 million Aptoide app store userssecurityaffairs.com (opens in a new tab)
- Android Police: Aptoide database breach exposes 20 million user accountsandroidpolice.com (opens in a new tab)
- Android Authority: Popular alternative app store Aptoide suffers major data breachandroidauthority.com (opens in a new tab)
- INCIBE-CERT: Data from millions of Aptoide users exposedincibe.es (opens in a new tab)
