Data breach
Badoo
- Records
- 125,324,194
- Breach date
- 1 June 2013Estimated
- Added
- 1 December 2024
What was exposed
4 types of data · 2 more reported · 1 puts you at serious risk
- Email addresses125,320,945
- Usernames125,090,738
- Passwords124,756,044
- Names67,181,180
- Dates of birthReported, not counted
- GenderReported, not counted
Reported in the breach write-up; not counted in the analysed data.
About this breach
In June 2013, the dating and social networking service Badoo was allegedly breached, and details of the incident only surfaced three years later. The dataset tied to this listing contains roughly 125.3 million records, including more than 125 million email addresses, about 124.8 million passwords, over 125 million nicknames, and around 67.2 million names. The data was found circulating among online traders in June 2016, and independent databases have since categorized the breach as unverified, meaning indicators suggest it is real but its legitimacy could not be conclusively proven. BreachHistory reports that Badoo denied being hacked, and no confirmed technical details about how the data was obtained have been published.
Limited public reporting: As of September 25, 2026, detailed company notices or major news coverage for this listing were limited in sources reviewed. The facts below rely primarily on the indexed fields plus any secondary sources cited.
Breach Timeline
June 2016: A dataset allegedly taken from Badoo was found circulating among online data traders, according to coverage by BreachHistory and Lunar Cyber.
July 6, 2016: The breach was verified and added to Mozilla Monitor, which lists the attack date as June 1, 2013.
What Information Was Compromised?
Our analysis found the following data types in this breach: nicknames, passwords, email addresses, and names.
The number of records varies by field. Email addresses appear in roughly 125.3 million entries and passwords in about 124.8 million, while names appear in about 67.2 million entries, according to the investigation team. Secondary reporting indicates the dataset also included usernames, full birthdates, and genders, and that passwords were stored as MD5 hashes, a weak and outdated hashing method that is easier to crack than modern approaches (Lunar Cyber).
Not every individual is affected by every type of data listed here.
What Are the Potential Risks for Affected Individuals?
The most immediate risk is account compromise. With more than 124 million password entries in the dataset, anyone whose password appears in the leak could have that password tested against other services. Because people often reuse passwords across sites, an exposed Badoo password may also unlock email, banking, or social media accounts.
The combination of email addresses, real names, and nicknames gives criminals material for targeted phishing. Messages that reference your name or the dating service itself can appear more convincing and are often used to trick people into revealing more credentials or personal information.
The presence of birthdates and gender information adds to the picture criminals can build about a person, which raises the risk of identity-related fraud and socially engineered scams.
Because the passwords in this dataset were reportedly protected only by MD5 hashing, attackers who obtain them can attempt to recover the original passwords with relatively modest computing resources, especially for simple or common passwords.
What Should You Do If You Were Affected?
If you had a Badoo account around 2013, take these steps:
Change your Badoo password, and if you used the same password anywhere else, change it there too. Each account should have a unique password.
Use a password manager to generate and store strong, distinct passwords for every service.
Turn on two-factor authentication wherever it is offered, starting with your email account, which protects access to password resets for everything else.
Watch for phishing emails that reference Badoo or dating services, and avoid clicking links or entering credentials from unsolicited messages.
Review your financial and other sensitive accounts for unfamiliar activity, and be alert to identity-related warning signs if your name and birthdate were part of the exposed data.
