Breach report
Social MediaMyspace
Recently confirmed Myspace hack could be the largest yet
More than 360 million Myspace accounts created before mid-2013, with emails and weakly hashed passwords, surfaced for sale in 2016, making it one of the largest credential dumps ever recorded.
Reported by TechCrunch
Records exposed
360M
More than 360 million accounts
Scale vs. largest on file
- When
- Pre-2013 (disclosed 2016)
- How they got in
- Database theft; weakly hashed passwords
- Sector
- Social Media
In late May 2016, Time Inc., which had recently acquired Myspace through its purchase of ad-tech company Viant, confirmed that a large trove of old Myspace account data had been stolen. The now-defunct breach search site LeakedSource said the dataset contained more than 360 million accounts and some 427 million passwords, making it one of the largest collections of stolen credentials ever reported at the time.
The data covered accounts created before June 11, 2013, when Myspace relaunched with a redesigned platform and stronger security. Each record included an email address and a password, and some accounts had a second password stored as well. The passwords had been hashed with SHA-1 without salting, which meant they could be cracked rapidly, and analysts found huge numbers of trivially weak choices. The data was attributed to the same Russian seller known as Peace who was marketing the LinkedIn and Tumblr dumps in the same period.
Myspace said current systems were not affected and that the breach predated the security overhaul. The company invalidated passwords for all affected accounts, pushed users to reset them, and said it was using automated tools to flag suspicious activity. It also said it was cooperating with law enforcement. Exactly when and how the original theft occurred has never been publicly established, and no one has been publicly charged over it.
Because Myspace had faded as a social network, many affected people had long forgotten their accounts. That was precisely what made the dump dangerous: users who had reused old Myspace passwords on email, banking or newer social platforms were exposed to credential-stuffing attacks years later. Within weeks of the disclosure, several high-profile social media accounts were hijacked in attacks linked to recycled credentials from these mega-breaches.
The Myspace breach is a reminder that data from dormant accounts does not expire. Companies that acquire older platforms inherit their security debt, including legacy password storage, and have an obligation to purge or re-secure stale data. For individuals, it reinforced the value of closing unused accounts, never reusing passwords, and checking services like Have I Been Pwned to learn whether old credentials are circulating.