Cyber Security News

Raaga Data Breach Exposes 10.2 Million User Records

Raaga suffered a significant data breach in December 2025, compromising the personal information of 10.2 million users.

The stolen database was subsequently offered for sale on a prominent underground hacking forum, raising serious concerns about user privacy and platform security.

According to HIBP, the breach was detected when threat actors posted the alleged Raaga database on a cybercrime marketplace. The compromised dataset contains approximately 10 million unique email addresses alongside extensive personal information.

Attackers are actively marketing this stolen data to potential buyers on dark web forums, increasing the risk of secondary attacks against affected users.

The breach timeline indicates the data was exfiltrated sometime in December 2025, though the exact date of the initial compromise remains unclear.

Raaga has not publicly disclosed when they discovered the security incident or whether affected users received breach notifications.

Compromised Information

The exposed database includes sensitive personal details that could facilitate identity theft and targeted phishing campaigns. Affected users had the following information compromised:

  • Full names and email addresses
  • Gender information
  • Age data and partial dates of birth
  • Geographic location data, including postal codes
  • Account passwords stored as unsalted MD5 hashes

The most critical security vulnerability lies in Raaga’s password storage methodology. The platform used unsalted MD5 hashing, an outdated and cryptographically weak algorithm that security experts abandoned years ago.

Modern password cracking tools can rapidly reverse MD5 hashes, allowing attackers to obtain plaintext passwords within hours or days.

Individuals who reuse passwords across multiple platforms face an elevated risk of credential stuffing attacks.

Affected Raaga users should immediately change their account passwords and enable two-factor authentication if available. Anyone using similar passwords on other services should update those credentials as well.

Users should remain vigilant against phishing emails that leverage stolen personal information and monitor their financial accounts for suspicious activity.

Follow us on Google News, LinkedIn, and X for daily cybersecurity updates. Contact us to feature your stories.

Guru Baran

Gurubaran KS is a cybersecurity analyst, and Journalist with a strong focus on emerging threats and digital defense strategies. He is the Co-Founder and Editor-in-Chief of Cyber Security News, where he leads editorial coverage on global cybersecurity developments.

Recent Posts

Google Chrome 153 Update Fixes 42 Security Flaws, Including 3 Critical Ones

Google has released an important Chrome 153 security update that fixes 42 vulnerabilities across the…

4 hours ago

CISA and NIST Release Technical Checklist for Safeguarding Identity Tokens From Theft and Misuse

The Cybersecurity and Infrastructure Security Agency (CISA) and the National Institute of Standards and Technology…

14 hours ago

CISA Shares 17 Techniques Used by Hackers to Compromise Active Directory Environments

CISA and five international cybersecurity agencies have released detailed guidance describing 17 common techniques hackers…

15 hours ago

Apple Rolls Out Massive Security Update Fixing 273 Vulnerabilities Across Its Devices

Apple has released one of its largest coordinated security rollouts, addressing 273 distinct critical vulnerabilities…

15 hours ago

How to Keep Malware’s Rotating Infrastructure From Becoming a Detection Gap

You can’t detect today's attacks with yesterday’s threat intelligence; that’s how you could briefly formulate…

15 hours ago

Microsoft Bans Its AI Models From Launching Cyberattacks or Escalating Their Own Access

Microsoft has published a draft Humanist AI Code of Conduct that would prohibit its in-house…

15 hours ago