Data breaches
MyFitnessPal data breach: what actually happened
There is not one 2025 MyFitnessPal breach. Searches using that phrase are usually picking up three separate events, spread across three different companies and eight years. This guide separates them so you can work out which, if any, actually involves your data.
The short answer
In The Event Of is an Australian digital footprint manager that helps you find the accounts linked to your email, see your breach exposure, and get a prioritised plan of what to do after a breach or a life change.
Key takeaways
- The only confirmed breach of MyFitnessPal's own systems was in 2018, not 2025.
- Under Armour's November 2025 breach hit its retail systems, years after it sold MyFitnessPal in 2020.
- The March 2026 Cal AI claim is unconfirmed and, on current reporting, involves Cal AI's systems only.
- None of the three incidents has been reported to include full credit card numbers or plaintext passwords.
- If you reused a password across any of these services, that is the risk worth acting on today.
Overview
Why three incidents keep getting reported as one
MyFitnessPal is the calorie and food-tracking app now owned by Francisco Partners, which acquired it from Under Armour in 2020. Because ownership has changed hands more than once, and because Under Armour, the former owner, had its own major breach in late 2025, search results and news coverage genuinely blur together.
The three events below are distinct. They involve different companies, different systems, different dates and different data. Working out which one a headline is describing is the first step to knowing whether it affects you at all.
Incident 1
The original MyFitnessPal breach, February to March 2018
Under Armour, which owned MyFitnessPal at the time, disclosed that an unauthorised party had acquired data from roughly 150 million user accounts. The intrusion was detected in late February 2018 and disclosed publicly on 29 March 2018. This remains the largest confirmed MyFitnessPal-related breach.
What was exposed: usernames, email addresses and hashed passwords. No financial data and no precise location data were reported as part of this incident.
Incident 2
The Under Armour breach, November 2025
This was a separate, later incident affecting Under Armour's own retail systems. By then, Under Armour no longer owned MyFitnessPal, having sold it in 2020. The Everest ransomware group claimed responsibility, and Under Armour confirmed around 72 million customer records were affected after refusing to pay.
Full details are on our Under Armour 2025 breach page. This is the likely source of most “2025” search traffic landing on MyFitnessPal queries.
Under Armour 2025 is not a MyFitnessPal breach
Incident 3
The Cal AI incident, March 2026
MyFitnessPal acquired the calorie-tracking app Cal AI in early March 2026. Within days, hackers claimed to have breached Cal AI's own systems, alleging exposure of over 3 million users. The claim is unconfirmed by Cal AI or MyFitnessPal, and reporting indicates only Cal AI's systems were implicated, not MyFitnessPal's core account database.
Unconfirmed as of writing
Side by side
What was exposed in each incident
| Incident | Date | Accounts | Data types |
|---|---|---|---|
| MyFitnessPal | Feb to Mar 2018 | ~150 million | Usernames, email addresses, hashed passwords (no financial data or precise location) |
| Under Armour | Nov 2025 | ~72 million | Names, emails; subset had date of birth, gender, address-derived location, purchase history |
| Cal AI (alleged) | Mar 2026 | 3 million+ | Names, usernames, dates of birth, gender, PINs, subscription details, height/weight, meal logs |
None of the three incidents has been reported to include full credit card numbers or plaintext passwords.
Are you affected?
Which one applies to you
You may be affected if any of these apply:
- You had a MyFitnessPal account before March 2018, the original breach.
- You were an Under Armour customer, via website, app or in-store loyalty account, before November 2025.
- You used the Cal AI app before March 2026, even if you have since migrated to MyFitnessPal.
If you have used the same email across any of these services, or reused a password, the safest approach is to check your exposure rather than guess.
Check my exposure, free
In The Event Of checks your email against known breaches, including these, and maps every account still linked to it. No credit card required.
Action plan
What to do now
- Check your exposure (5 minutes). Run your email through a free breach check to see which of these, if any, actually involves your address. See also what to do if your email is in a data breach.
- Change your MyFitnessPal password, even if unaffected (2 minutes). If it is old or reused elsewhere, update it now and turn on two-factor authentication if offered.
- Check for password reuse (10 minutes). If your MyFitnessPal or Under Armour password is used on any other account, such as email, banking or social, change it there too.
- Watch for phishing referencing fitness or purchase data (ongoing). Scammers use exposed details like purchase history or weight and height data to make phishing emails feel personal and legitimate.
- Consider a credit ban if your date of birth was exposed (15 minutes). This applies mainly to the Under Armour or Cal AI incidents. Contact Australia's credit reporting bodies, Equifax and Experian, which has now acquired illion, to place a ban on new credit applications in your name.
- Report anything suspicious (5 minutes). Report phishing attempts to Scamwatch, and call IDCARE on 1800 595 160 if you suspect identity misuse.
Password reuse is the real carry-over risk
Using In The Event Of
How In The Event Of helps
In The Event Of is built around turning scattered account records into a single map. You can connect a supported inbox (Gmail or Outlook) so it can scan for account-related metadata, sender addresses, subject lines and timestamps rather than the body of your emails, or add services manually. It then organises what it finds into a digital footprint, highlights breach exposure across known incidents, and gives you guided steps for each account, including old fitness and retail accounts you may have forgotten. You stay in control of every change. If you would rather work through it by hand first, our guide to finding accounts linked to your email covers the manual process.
FAQ
Frequently asked questions
Was MyFitnessPal breached in 2025?
Is the 2018 MyFitnessPal breach still relevant?
What is the Cal AI data breach and does it affect my MyFitnessPal account?
Is MyFitnessPal safe to use now?
How do I know if my email was in any of these breaches?
Should I delete my MyFitnessPal account over this?
Sources
Where this information comes from
- Under Armour, Under Armour Notifies MyFitnessPal Users of Data Security Issue (29 March 2018, filed with the SEC)
- OAIC, Notifiable Data Breaches scheme
- ACSC, Australian Cyber Security Centre
- Scamwatch, Report a scam
- IDCARE, Australia's national identity and cyber support service (1800 595 160)
- Hackread, MyFitnessPal-Owned Cal AI Hit by Data Breach Affecting 3M Users (March 2026)
- Cybernews, Cal AI allegedly breached, hackers expose user data (March 2026)
Related guides
Email in a data breach
Data breaches
Best footprint tools (AU)
Tools & comparisons
Find accounts linked to your email
Digital footprint
Incogni vs DeleteMe (AU)
Tools & comparisons
Find accounts linked to your phone
Digital footprint
Have I Been Pwned explained
Data breaches
Delete old accounts
Digital footprint
Remove personal info (AU)
Digital footprint
Digital footprint checklist
Digital footprint
Password manager vs breach monitor
Tools & comparisons
Secure your email after a breach
Account security
What data companies store
Digital footprint
Moving house address checklist
Life admin
Disclaimer: Breach details are summarised from company disclosures and published reporting at the time of writing. The Cal AI incident remains unconfirmed by the companies involved and details may change. This guide is general information only and is not legal, financial, or security advice. It is based on publicly available sources at the time of writing and may not reflect the most recent developments. In The Event Of Pty Ltd (ABN 38 687 352 647) is an independent Australian company and is not affiliated with the third-party services named in this guide.