ADVERTISEMENT

Android fiction apps expose millions of readers and writers

An unsecured server has exposed 100 million data records of readers and writers using some of the internet’s largest fiction apps.

Popular Android apps leak personal user details
Paulina Okunytė
Paulina Okunytė Senior Journalist
November 26, 2025 Updated: November 26, 2025 3 min read
Key takeaways:
Jurgita Lapienyte justinasv Izabele Pukenaite vilius Ernestas Naprys Gintaras Radauskas
Don't miss our latest stories on Google News. Add us as your Preferred Source on Google
Add us as your Preferred Source on Google.

What readers’ data was leaked?

  • Emails
  • Full names
  • Password hashes (md5)
  • Phone numbers
  • Gender
  • Device metadata
  • Reading history
  • Bookshelf activity
  • Interaction logs
  • Behavioral analytics
Android flaw
Image by Cybernews.

What author data has been leaked?

  • Email
  • Real name
  • Pseudonym
  • Full address, including city, ZIP code, and state or country
  • Personal ID number and direct S3-style path to uploaded ID card image
  • Age and nationality declarations
  • Book information, including book title, status, genre, planned chapters, and writing status
  • Editorial metadata, including editor name and reviewer identifiers tied to the publishing workflow
  • Platform contract details, including contract type, status, buyout fee, payment structures, and profit share parameters
  • Narrative outline, including detailed book synopses, often in raw text format with explicit plot content, as part of their application or contract submission
  • Sensitive contract metadata, including profit-sharing models and editorial evaluations in plain text

Readers and writers at risk

ADVERTISEMENT
Has my data been leaked?
android malware
Image by Cybernews.

Who is responsible for the data leak?

Disclosure timeline

  • Initial disclosure: June 3rd, 2025
  • Disclosure to GoodNovel and Webfic: October 1st, 2025
  • CERT contacted: October 9th, 2025
  • Leak closed: November 6th, 2025

ADVERTISEMENT