Data breaches

MyFitnessPal data breach: what actually happened

There is not one 2025 MyFitnessPal breach. Searches using that phrase are usually picking up three separate events, spread across three different companies and eight years. This guide separates them so you can work out which, if any, actually involves your data.

Last updated: 31 May 2026Independent guidance, Australia-first

The short answer

The real MyFitnessPal hack happened in March 2018: about 150 million accounts, with usernames, emails and hashed passwords taken. Separately, Under Armour, which owned MyFitnessPal until 2020, suffered its own ransomware breach in November 2025, unrelated to the fitness app. Then in March 2026, Cal AI, a calorie-tracking app MyFitnessPal had just acquired, reported an alleged breach of its own user data. None of these mean your current MyFitnessPal login was compromised in 2025, but it is worth checking each one below.

In The Event Of is an Australian digital footprint manager that helps you find the accounts linked to your email, see your breach exposure, and get a prioritised plan of what to do after a breach or a life change.

Australian & independentThird-party security assessmentSources cited

Key takeaways

  • The only confirmed breach of MyFitnessPal's own systems was in 2018, not 2025.
  • Under Armour's November 2025 breach hit its retail systems, years after it sold MyFitnessPal in 2020.
  • The March 2026 Cal AI claim is unconfirmed and, on current reporting, involves Cal AI's systems only.
  • None of the three incidents has been reported to include full credit card numbers or plaintext passwords.
  • If you reused a password across any of these services, that is the risk worth acting on today.

Overview

Why three incidents keep getting reported as one

MyFitnessPal is the calorie and food-tracking app now owned by Francisco Partners, which acquired it from Under Armour in 2020. Because ownership has changed hands more than once, and because Under Armour, the former owner, had its own major breach in late 2025, search results and news coverage genuinely blur together.

The three events below are distinct. They involve different companies, different systems, different dates and different data. Working out which one a headline is describing is the first step to knowing whether it affects you at all.

Incident 1

The original MyFitnessPal breach, February to March 2018

Under Armour, which owned MyFitnessPal at the time, disclosed that an unauthorised party had acquired data from roughly 150 million user accounts. The intrusion was detected in late February 2018 and disclosed publicly on 29 March 2018. This remains the largest confirmed MyFitnessPal-related breach.

What was exposed: usernames, email addresses and hashed passwords. No financial data and no precise location data were reported as part of this incident.

Incident 2

The Under Armour breach, November 2025

This was a separate, later incident affecting Under Armour's own retail systems. By then, Under Armour no longer owned MyFitnessPal, having sold it in 2020. The Everest ransomware group claimed responsibility, and Under Armour confirmed around 72 million customer records were affected after refusing to pay.

Full details are on our Under Armour 2025 breach page. This is the likely source of most “2025” search traffic landing on MyFitnessPal queries.

Under Armour 2025 is not a MyFitnessPal breach

Under Armour sold MyFitnessPal in 2020. The November 2025 incident affected Under Armour's retail customer records, not MyFitnessPal's account database. If you shopped with Under Armour but never used the app, this is the one that concerns you.

Incident 3

The Cal AI incident, March 2026

MyFitnessPal acquired the calorie-tracking app Cal AI in early March 2026. Within days, hackers claimed to have breached Cal AI's own systems, alleging exposure of over 3 million users. The claim is unconfirmed by Cal AI or MyFitnessPal, and reporting indicates only Cal AI's systems were implicated, not MyFitnessPal's core account database.

Unconfirmed as of writing

Neither Cal AI nor MyFitnessPal has confirmed this breach. The figures below come from the attackers' claim as reported, and the confirmation status may change. Treat it as an allegation, not an established fact.

Side by side

What was exposed in each incident

Comparison of the three incidents commonly reported as the MyFitnessPal breach
IncidentDateAccountsData types
MyFitnessPalFeb to Mar 2018~150 millionUsernames, email addresses, hashed passwords (no financial data or precise location)
Under ArmourNov 2025~72 millionNames, emails; subset had date of birth, gender, address-derived location, purchase history
Cal AI (alleged)Mar 20263 million+Names, usernames, dates of birth, gender, PINs, subscription details, height/weight, meal logs

None of the three incidents has been reported to include full credit card numbers or plaintext passwords.

Are you affected?

Which one applies to you

You may be affected if any of these apply:

  • You had a MyFitnessPal account before March 2018, the original breach.
  • You were an Under Armour customer, via website, app or in-store loyalty account, before November 2025.
  • You used the Cal AI app before March 2026, even if you have since migrated to MyFitnessPal.

If you have used the same email across any of these services, or reused a password, the safest approach is to check your exposure rather than guess.

Check my exposure, free

In The Event Of checks your email against known breaches, including these, and maps every account still linked to it. No credit card required.

Check my exposure free

Action plan

What to do now

  1. Check your exposure (5 minutes). Run your email through a free breach check to see which of these, if any, actually involves your address. See also what to do if your email is in a data breach.
  2. Change your MyFitnessPal password, even if unaffected (2 minutes). If it is old or reused elsewhere, update it now and turn on two-factor authentication if offered.
  3. Check for password reuse (10 minutes). If your MyFitnessPal or Under Armour password is used on any other account, such as email, banking or social, change it there too.
  4. Watch for phishing referencing fitness or purchase data (ongoing). Scammers use exposed details like purchase history or weight and height data to make phishing emails feel personal and legitimate.
  5. Consider a credit ban if your date of birth was exposed (15 minutes). This applies mainly to the Under Armour or Cal AI incidents. Contact Australia's credit reporting bodies, Equifax and Experian, which has now acquired illion, to place a ban on new credit applications in your name.
  6. Report anything suspicious (5 minutes). Report phishing attempts to Scamwatch, and call IDCARE on 1800 595 160 if you suspect identity misuse.

Password reuse is the real carry-over risk

The 2018 passwords were hashed, but hashes can be cracked offline over time. If the password you used on MyFitnessPal in 2018 still protects your email or banking today, that is the single most urgent thing on this page.

Using In The Event Of

How In The Event Of helps

In The Event Of is built around turning scattered account records into a single map. You can connect a supported inbox (Gmail or Outlook) so it can scan for account-related metadata, sender addresses, subject lines and timestamps rather than the body of your emails, or add services manually. It then organises what it finds into a digital footprint, highlights breach exposure across known incidents, and gives you guided steps for each account, including old fitness and retail accounts you may have forgotten. You stay in control of every change. If you would rather work through it by hand first, our guide to finding accounts linked to your email covers the manual process.

FAQ

Frequently asked questions

Was MyFitnessPal breached in 2025?
No confirmed MyFitnessPal breach occurred in 2025. The '2025' search queries mostly stem from Under Armour's November 2025 ransomware breach. Under Armour owned MyFitnessPal until 2020 but had already sold it by 2025. The two are separate incidents affecting different companies and systems.
Is the 2018 MyFitnessPal breach still relevant?
Yes, if you had an account before March 2018 and have not changed your password since. Around 150 million accounts had usernames, emails and hashed passwords exposed. If you reused that password elsewhere, change it now on every account that shares it.
What is the Cal AI data breach and does it affect my MyFitnessPal account?
Cal AI is a calorie-tracking app MyFitnessPal acquired in March 2026. Days later, hackers claimed to have breached Cal AI's own systems, affecting over 3 million users, unconfirmed as of writing. Reporting indicates only Cal AI's systems were involved, not MyFitnessPal's main account database.
Is MyFitnessPal safe to use now?
There is no evidence of an active breach affecting current MyFitnessPal accounts. Like any app storing personal data, risk depends on your password hygiene and what permissions you have granted. Use a unique password, enable two-factor authentication, and check periodically for exposure.
How do I know if my email was in any of these breaches?
The fastest way is a free breach check against your email address, which also maps other accounts linked to that address so you can prioritise which passwords to change first. No credit card required.
Should I delete my MyFitnessPal account over this?
Not necessarily. None of the three incidents shows a confirmed, current breach of MyFitnessPal's own systems. If you are concerned, tighten your password and privacy settings first, and revisit deletion only if new evidence of a direct MyFitnessPal breach emerges.

Disclaimer: Breach details are summarised from company disclosures and published reporting at the time of writing. The Cal AI incident remains unconfirmed by the companies involved and details may change. This guide is general information only and is not legal, financial, or security advice. It is based on publicly available sources at the time of writing and may not reflect the most recent developments. In The Event Of Pty Ltd (ABN 38 687 352 647) is an independent Australian company and is not affiliated with the third-party services named in this guide.