[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f3m558ta4in6sc":3},{"success":4,"breach":5},true,{"_id":6,"name":7,"title":8,"slug":9,"domain":10,"breachDate":11,"addedDate":12,"modifiedDate":12,"contentUpdatedAt":13,"source":14,"sourceUrl":15,"sourceUrls":16,"pwnCount":19,"affectedCount":19,"affectedCountStatus":20,"affectedCountLowerBound":21,"affectedCountUnit":22,"hasEnglishDescription":4,"severity":23,"dataClasses":24,"description":29,"seoTitle":30,"seoTitleEn":31,"seoDescription":30,"seoDescriptionEn":32,"logoUrl":33,"isVerified":4,"isSensitive":34,"isSpamList":34,"isMalware":34,"company":35},"68e3266eda11adda48825266","Lastfm","Last.fm Data Breach","lastfm","last.fm","2012-03-22T00:00:00.000Z","2016-09-20T20:00:49.000Z","2026-07-18T23:53:03.754Z","Verified breach record","https:\u002F\u002Fblog.last.fm\u002F2012\u002F06\u002F08\u002Fan-update-on-lastfm-password-security",[15,17,18],"https:\u002F\u002Ftechcrunch.com\u002F2016\u002F09\u002F01\u002F43-million-passwords-hacked-in-last-fm-breach\u002F","https:\u002F\u002Fwww.securityweek.com\u002F43-million-lastfm-accounts-stolen-2012-breach\u002F",37217682,"known",null,"unknown","Critical",[25,26,27,28],"Email addresses","Passwords","Usernames","Website activity","\u003Cp>The Last.fm data breach is related to the compromise of account information belonging to Last.fm users in March 2012. The incident was initially noticed in a limited way through password hashes; the actual size of the affected data set became clearer in September 2016 with files made public. The verified query set contains 37,217,682 unique email addresses. Data fields include email addresses, usernames, passwords, and website activity. The fact that passwords are in unsalted MD5 hashes poses a high risk of account takeover, especially for people who use the same password across different services.\u003C\u002Fp>\n\u003Ch2>Leaked Data Types and Risks\u003C\u002Fh2>\n\u003Cp>The main fields confirmed in the Last.fm leak are email addresses, usernames, passwords, and website activity. When the email address and username are seen together, attackers can prepare personalized password attempts, fake security alerts, and account recovery messages. Website activity, on the other hand, increases the social engineering risk through the user's music account preferences, profile usage, and behaviors associated with the service.\u003C\u002Fp>\n\u003Cp>The presence of passwords as unsalted MD5 hashes is the most critical part of the risk. MD5 is weak according to modern security standards; passwords stored without a salt value can be cracked faster using dictionary and precomputed hash lists. If the same password is repeated across email, social media, music, gaming, or shopping accounts, attackers may try the compromised credentials on other services. Therefore, the Last.fm result is not just a warning about an old music account, but a high-priority account security indicator that requires stopping password reuse.\u003C\u002Fp>\n\u003Ch2>Verified Scope and Boundaries\u003C\u002Fh2>\n\u003Cp>The date of the breach is March 2012. The service issued a user warning about password security in 2012, but the true scale of the dataset became more widely known in 2016. The verified account set contains 37,217,682 unique email addresses; in broader reports of the incident, around 43 million account rows are mentioned. This difference arises from duplicate accounts, email cleaning, and the distinction between verifiable unique records.\u003C\u002Fp>\n\u003Cp>The data classes on this page are limited to fields that can be verified in an account security query: email addresses, passwords, usernames, and website activity. Technical details that are not confirmed regarding the incident or additional profile fields that have not been verified as applicable to each user are not presented here as primary data fields. The goal is to show users where the real risk is concentrated and to highlight the correct security actions without generating unnecessary fear.\u003C\u002Fp>\n\u003Ch2>User Groups at Risk\u003C\u002Fh2>\n\u003Cp>People who have a Last.fm account, use the same username on different platforms, and reuse old passwords are the main risk group. Since music services are often used together with social profiles, usernames, and other platform connections, attackers can look for the same identity on different sites. The old username still appearing on social media, email, or gaming accounts increases the risk of account matching.\u003C\u002Fp>\n\u003Cp>People who reuse passwords are at higher risk. Even if the password used in 2012 is no longer in use today, if there are new passwords derived from the same password pattern, attackers may try similar variations. If the email account is affected by the same password family, the password reset flows of other accounts may also be targeted. Since music preferences and profile behavior can be used in personalized fake messages, the risk of phishing should not be ignored either.\u003C\u002Fp>\n\u003Ch2>Urgent Measures to Be Taken\u003C\u002Fh2>\n\u003Cp>Password changes should be carried out immediately on all accounts where the same or similar password is used as with Last.fm. The new password should be unique, long, and random; it should be stored with a password manager. Priority should be given to email accounts, social media, music services, gaming accounts, and platforms containing payment information. Adding a number to the end of the old password or trying small letter changes does not provide sufficient protection.\u003C\u002Fp>\n\u003Cp>Multi-factor authentication should be enabled on every account that supports it. The login history, recovery addresses, forwarding rules, and unknown devices in the email account should be checked. Care should be taken against fake security alerts using the Last.fm or music services theme, song-sharing links, profile verification messages, and password reset requests. The domain name should be checked before clicking on a link, and passwords should not be entered through suspicious messages.\u003C\u002Fp>\n\u003Ch2>Long-Term Security Strategies\u003C\u002Fh2>\n\u003Cp>The Last.fm incident shows that a violation that happened many years ago can still affect account security today. Users should regularly review their old passwords, should not reuse the same password across different services, and should use email aliases whenever possible. If social profile names, music accounts, and forum usernames are very similar, it becomes easier for attackers to link accounts.\u003C\u002Fp>\n\u003Cp>For permanent protection, a password manager, unique password policy, multi-factor authentication, and session notifications should be used together. Unused old accounts should be closed or at least secured with a strong password. In corporate environments, to prevent employees from repeating personal music and social account passwords on work accounts, leaked password checks, security training, and additional verification policies should be implemented.\u003C\u002Fp>\n\u003Ch2>Record Control and User Action\u003C\u002Fh2>\n\u003Cp>If the Last.fm result appears in the account security check, it means that the relevant email address is included in the verified account set associated with the 2012 Last.fm data breach. This result does not mean that your current Last.fm account has been compromised today; however, it indicates that the username, email address, and password information used in the past may be at risk of being misused. The risk is higher if the same password was used on other accounts.\u003C\u002Fp>\n\u003Cp>The first step is to secure your email account, then individually update all accounts that use the same or similar password. If there are suspicious sessions, unknown devices, unexpected password reset messages, or strange notifications sent from your account, sessions should be terminated, and a review should be initiated through the security center of the relevant service. Completely stopping password reuse, updating old music and social accounts, and being cautious against phishing messages are the most effective user actions for Last.fm results.\u003C\u002Fp>","","Last.fm Data Breach (37.2 Million Reported Records)","Last.fm Data Breach. 37.2 Million reported records were reported. Reported data: Email addresses, Passwords, Usernames. Review the scope, risks, and…","\u002Fuploads\u002Flogo\u002Flast_fm.webp",false,{"name":36,"sector":37,"country":38,"website":10,"websiteArchiveUrl":30,"websiteStatus":30,"websiteCheckedAt":21},"Last.fm","Music streaming and recommendation service","United Kingdom"]