Wishbone 2016 Data Breach

Wishbone Social Polling App Breach (2016): 2.2 Million User Records Including Auth Tokens & Phone Numbers Exposed

Platform · Social polling and quizzes · Mobile social platform · Global

Wishbone Social Polling App Breach (2016): 2.2 Million User Records Including Auth Tokens & Phone Numbers Exposed

Social polling app.

Confirmed · ObscureIQ Intelligence
Breach Risk Index i
14/100
Lower riskHigher risk
Lower: limited current risk based on data value and recency.
Data Sensitivity i
Standard
Exposed data is largely lower-sensitivity. Standard identity-protection precautions are advised.
2.2MRecords
2016Year

The Breach Risk Index (BRI) is a proprietary 0–100 score rating how dangerous a breach is right now, based on how recently the data has been circulating on the dark web and how valuable it is to attackers.

Classification Tags
Cloud MisconfigurationSocial NetworkingCommunityUsers2016

Breach Summary

Wishbone, a mobile polling app popular among teenagers, suffered a data breach in 2016 stemming from a misconfiguration. The exposed dataset contained 9.4 million records in total, with 2.2 million unique email addresses identified. The breach is believed to represent only a subset of the full compromised data. The exposed information included names, usernames, email addresses, phone numbers, dates of birth, genders, and authentication tokens. Authentication tokens are credentials that keep users logged in to apps and services, and their exposure can allow attackers to access accounts without needing a password. Because Wishbone's user base skewed young and female, the presence of birth dates and phone numbers for potentially underage users raised particular concern. This combination of data enables account takeover, identity profiling, and targeted contact of minors. No specific legal actions or regulatory responses related to this breach are on record. Affected users, especially those who were minors at the time, face ongoing risks including unauthorized account access, social engineering, and the use of their personal details to build profiles for further exploitation. Those who used the same credentials elsewhere are advised to change their passwords on any linked accounts.

Full threat analysis, exploitation vectors, and principal guidance below.

10 additional sections · verified field analysis · defensive doctrine

Querying breach corpus…
Cross-referencing exposed field types…
Resolving threat-actor attribution…
Compiling principal risk advisory…

2.2M records analyzed

About Wishbone

Wishbone was a mobile social polling application that allowed users to compare two items by voting on which they preferred — essentially a digital "this or that" format. The app was particularly popular among teenage users and was noted for attracting a young, primarily female demographic. Wishbone experienced two distinct data breaches and has since shut down as an active platform.

Why They Hold Your Data

Social polling and quiz platforms collect user accounts, profile data, quiz responses, social activity, and engagement records tied to mobile social interaction.

Recent Developments

Wishbone no longer operates as an active platform. The app was discontinued, though the exact timeline of shutdown has not been prominently documented.

Data Points Exposed

7 verified field types
Authentication Token High
Date of Birth High
Email Address
Full Name
Gender
Phone Number
Username

Breach Impact

In August 2016 Wishbone suffered a breach exposing approximately 2.2 million unique email addresses alongside names, genders, birth dates, phone numbers, and auth tokens. The dataset was characterized as a subset of the full breach corpus. Given the platform's teen-heavy user base, the exposure of birth dates and phone numbers for potentially underage users drew particular concern.

Exploitation & Downstream Threats

• Identity verification bypass using name + date of birth combination | • SIM swap attacks where phone numbers are present | • Targeted phishing campaigns using exposed email addresses

Principal Risk Advisory

What this means for a principal

A social-platform breach: profile and contact-graph data supports impersonation, enrichment and social engineering. For a high-profile principal the main risk is credible impersonation and enrichment of existing exposure.

What You Should Do

  1. Reset any reused passwords and enable MFA on email first, then financial accounts.
  2. Guard against SIM-swap and vishing: add a carrier port-out PIN and verify any 'support' calls independently.
  3. Do not use unofficial 'am I affected' lookups; several are themselves harvesting operations.

How ObscureIQ Can Help

  1. Corpus confirmation: determine whether and where the principal (plus household and staff) appear in this dataset and which specific fields are exposed for them.
  2. Exposure mapping and footprint neutralization: cross-reference against broker-available data and suppress still-removable elements, prioritizing address and phone, since this record re-seeds broker networks.
  3. ThreatWatch tuned to this incident's identifiers and misuse pattern (impersonation and targeting patterns, not generic credential monitoring).

Protect Yourself

Check If You're Affected

Enter your email to check whether your data appears in this breach. We’ll send a 6-digit code to confirm it’s your address.

Get Free Breach Alerts

Be the first to know when new breaches are disclosed. Free forever — confirm your email with a 6-digit code.

High-Risk? Get an Exposure Audit

Executives, public figures, and high-visibility operators can receive tailored exposure intelligence and hardening guidance.

Request Consultation