[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f25suz2qysm6dx":3},{"success":4,"breach":5},true,{"_id":6,"name":7,"title":8,"slug":7,"domain":9,"breachDate":10,"addedDate":11,"modifiedDate":12,"contentUpdatedAt":13,"source":14,"sourceUrl":15,"sourceUrls":16,"pwnCount":19,"affectedCount":19,"affectedCountStatus":20,"affectedCountLowerBound":21,"affectedCountUnit":22,"hasEnglishDescription":4,"severity":23,"dataClasses":24,"description":27,"seoTitle":28,"seoTitleEn":29,"seoDescription":28,"seoDescriptionEn":30,"logoUrl":31,"isVerified":4,"isSensitive":32,"isSpamList":32,"isMalware":32,"company":33},"68e3266eda11adda488250ba","8tracks","8tracks Data Breach","8tracks.com","2017-06-27T00:00:00.000Z","2018-02-16T07:09:30.000Z","2019-08-25T08:52:21.000Z","2026-07-19T23:04:39.770Z","Database leak","https:\u002F\u002Fblog.8tracks.com\u002F2017\u002F06\u002F27\u002Fpassword-security-alert\u002F",[15,17,18],"https:\u002F\u002Fwww.infosecurity-magazine.com\u002Fnews\u002F8tracks-breach-exposes-18-million\u002F","https:\u002F\u002Fsecurityaffairs.com\u002F60556\u002Fdata-breach\u002F8tracks-data-leak.html",17979961,"known",null,"unknown","Critical",[25,26],"Email addresses","Passwords","\u003Cp>The June 2017 8tracks data breach affected 17,979,961 accounts and exposed email addresses together with password hashes.\u003C\u002Fp>\u003Ch2>Types of Exposed Data and Risks\u003C\u002Fh2>\u003Cp>The confirmed data classes are email addresses and password hashes. Password digests for accounts created with an email address and password were stored as salted SHA-1 hashes; passwords belonging to external social sign-in providers were not held by 8tracks and were not part of this incident. \u003Cstrong>The confirmed impact count of 17,979,961 accounts\u003C\u002Fstrong> is based on the complete dataset reviewed later. An initially verified subset contained almost 8 million unique email addresses, which explains why a much lower figure also appears in historical reporting; the two numbers do not describe the same scope. Salting adds protection, but SHA-1 is weak by modern standards and simple passwords remain vulnerable to offline guessing. Exposed email addresses may support phishing, spam and credential-stuffing attempts against unrelated services. Payment card numbers, telephone numbers and street addresses were expressly outside the confirmed scope, so they are not listed as exposed fields.\u003C\u002Fp>\u003Ch2>Breach Timeline and Technical Details\u003C\u002Fh2>\u003Cp>On 27 June 2017, 8tracks announced that it had received credible reports of a leaked copy of its user database. The company’s investigation attributed the likely entry point to an employee’s code-hosting account that was not protected by two-step verification. The access did not appear to involve a direct compromise of production database servers; instead, it opened a path to a storage system containing backups of user tables. The company secured the account and storage system, added backup access logging and strengthened two-step verification for staff. The first sample examined at the time held almost 8 million unique email addresses, while a later complete dataset established the confirmed total of 17,979,961 affected accounts. Treating the first sample as the full incident would therefore understate its reach. Listening history, playlists and payment information have not been verified in the leaked material and are deliberately excluded from the exposed-data classification.\u003C\u002Fp>\u003Ch2>User Groups at Risk\u003C\u002Fh2>\u003Cp>The highest-risk group consists of people who registered for 8tracks with an email address and password before the breach and reused the same or a similar password elsewhere. A password hash is not readable plain text, but attackers can test common guesses offline and recover weak choices. If a recovered password was also used for email, social media, shopping or cloud accounts, the 2017 incident can still lead to account takeover years later. \u003Cstrong>Passwords from external social sign-in providers were not exposed\u003C\u002Fstrong>, although users should separately check whether their email address appears in the dataset. Long, unique passwords substantially reduce cracking and reuse risk, yet targeted phishing and fraudulent password-reset messages remain relevant to every person whose address was exposed.\u003C\u002Fp>\u003Ch2>Immediate Steps to Take\u003C\u002Fh2>\u003Cp>If your 8tracks password is unchanged, or if the password you used in 2017 survives on any other account, replace every reused copy immediately. Generate a long, unique password for each service and prioritize your primary email account, password manager, financial services and social networks. Enable multi-factor authentication on email and other important accounts, preferably with an authenticator app or hardware security key instead of SMS where available. Review recovery addresses, active sessions, forwarding rules and recognized devices for changes you did not make. Do not follow urgent links in messages claiming to represent 8tracks or another service; navigate to the official site independently. Treat requests for your current password, password-reset code or one-time authentication code as suspicious.\u003C\u002Fp>\u003Ch2>Long-Term Security Strategies\u003C\u002Fh2>\u003Cp>The durable lesson from this breach is to prevent one historical password from linking multiple accounts. Use a password manager to generate random, unique credentials for every service and avoid recycling answers to account-recovery questions. Keep multi-factor authentication enabled on critical accounts, store recovery codes safely offline and review recovery options at regular intervals. Monitor unexpected sign-ins, password-reset requests and newly created forwarding rules. A dataset from 2017 may look old, but its risk remains current whenever any associated password is still in use. \u003Cstrong>Eliminating password reuse completely\u003C\u002Fstrong> is the most effective way to stop a password recovered from one breach being carried into other services. If you discover an unfamiliar session, change credentials from a trusted device, revoke all active sessions and reassess the permissions granted to connected applications.\u003C\u002Fp>\u003Ch2>Check Your Data\u003C\u002Fh2>\u003Cp>Use the secure search field on this page to check each email address you have used and determine whether it matches the 8tracks record. A match does not prove that your password was successfully recovered; it means the address appears in the verified breach dataset and that a password hash may have been exposed for accounts using direct email registration. If you receive a match, review not only 8tracks but every service where you used the same or a similar password in 2017. No match is an absolute guarantee; the address may appear in another dataset. Never enter your password into a breach search and never disclose a verification code sent to you. Rechecking both current and historical email addresses periodically can alert you when newly published breach records appear and gives you time to strengthen affected accounts before stolen information is used.\u003C\u002Fp>","","8tracks Data Breach (18 Million Reported Records)","8tracks Data Breach. 18 Million reported records were reported. Reported data: Email addresses, Passwords. Review the scope, risks, and protective steps.","\u002Fuploads\u002Flogo\u002F8tracks_com.webp",false,{"name":7,"sector":34,"country":35,"website":9,"websiteArchiveUrl":28,"websiteStatus":28,"websiteCheckedAt":21},"Online playlist and internet radio","United States"]