[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f3n9p6g7ne2yet":3},{"success":4,"breach":5},true,{"_id":6,"name":7,"title":8,"slug":7,"domain":9,"breachDate":10,"addedDate":11,"publishedAt":12,"modifiedDate":13,"contentUpdatedAt":14,"source":15,"sourceUrl":16,"sourceUrls":17,"pwnCount":18,"affectedCount":18,"affectedCountStatus":19,"affectedCountLowerBound":12,"affectedCountUnit":20,"hasEnglishDescription":4,"contentLocale":21,"availableLocales":22,"translations":24,"severity":27,"dataClasses":28,"description":35,"seoTitle":36,"seoDescription":37,"logoUrl":38,"isVerified":4,"isSensitive":39,"isSpamList":39,"isMalware":39,"company":40},"6a452308a20f867c8ba8e754","songtrivia2","SongTrivia2 Data Breach","songtrivia2.io","2026-04-02T00:00:00.000Z","2026-04-04T01:59:01.000Z",null,"2026-07-03T09:06:32.828Z","2026-07-19T00:02:59.527Z","Third party breach","",[],291739,"known","unknown","en",[21,23],"tr",{"en":25,"tr":26},{"slug":7},{"slug":7},"High",[29,30,31,32,33,34],"Auth tokens","Avatars","Email addresses","Names","Passwords","Usernames","\u003Cp>The SongTrivia2 data breach was recorded in April 2026 as an incident affecting user accounts on the music trivia platform. The dataset, containing approximately 292,000 unique email addresses, included auth token information, avatars, names, usernames, and passwords stored in bcrypt format. Since some of the data appeared to come from accounts logged in via Google OAuth and some from accounts created directly on the site, the risk should be evaluated in terms of both social login and traditional membership security.\u003C\u002Fp> \u003Ch2>Leaked Data Types and Risks\u003C\u002Fh2> \u003Cp>The data types listed in this record are Auth tokens, Avatars, Email addresses, Names, Passwords, and Usernames. The Auth tokens field is particularly important because token data can, in some cases, pose session context or authorization risks without knowing the password. Users need to log out of active sessions on the platform, review permissions for connected applications, and perform security checks on other entertainment or social platforms that use the same email address.\u003C\u002Fp> \u003Ch2>Password and Token Risk\u003C\u002Fh2> \u003Cp>The password field poses a critical risk for users who create site accounts directly. Although the use of Bcrypt makes the attacker's job more difficult, the danger persists with weak and reused passwords. If the password used on the SongTrivia2 account has been repeated on other services, it should be changed, prioritizing email, social media, gaming, and music platforms in particular. A password manager and multi-factor authentication help mitigate this risk.\u003C\u002Fp> \u003Ch2>Profile ID and Avatar Matching\u003C\u002Fh2> \u003Cp>Avatar, display name, and username fields can link a user's online identity across different platforms. It is common for the same avatar or nickname to be reused in music, gaming, and social trivia communities. Therefore, an attacker could use the profile information from a SongTrivia2 account to find other accounts or prepare personalized messages. Users should minimize unnecessary personal information on public profiles.\u003C\u002Fp> \u003Ch2>Connected App Permissions\u003C\u002Fh2> \u003Cp>Due to the auth token and social login context, it may not be sufficient for affected individuals to only change their password. If login was used through a Google account or another provider, the list of connected apps should be checked, unused permissions should be removed, and security activities should be reviewed. If an unexpected session, new device, or unknown app permission is observed, the relevant sessions should be closed.\u003C\u002Fp> \u003Cp>On entertainment platforms like SongTrivia2, users may not take security warnings as seriously as they would for a financial service. However, when fields such as email, username, avatar, and auth token are combined, there is a risk of both account takeover and identity matching. Attackers may direct the user to a link with messages such as fake contests, rewards, score notifications, profile verification, or friend invitations.\u003C\u002Fp> \u003Ch2>Verified Scope and Boundaries\u003C\u002Fh2> \u003Cp>This record does not mean that all fields are present for every user. Accounts opened with social login may not have a password; for those who create an account directly on the site, the password field may become more critical. Although this distinction changes the risk for users, steps such as email security, logging out, and checking connected app permissions are important for all affected individuals.\u003C\u002Fp> \u003Ch2>Necessary Precautions\u003C\u002Fh2> \u003Cp>Affected users should be careful with unexpected messages coming in the context of SongTrivia2 or music trivia. Messages requesting rewards, leaderboards, account verification, avatar updates, new sign-ins, or social connections should be checked independently. The most accurate approach is to make passwords unique, clear permissions for connected applications, and review privacy settings on other social accounts using the same username.\u003C\u002Fp> \u003Cp>Users with accounts using social login may often see the risk as low, thinking there is no separate password. However, auth tokens and linked app permissions can show which services the account is associated with. Therefore, actions should be taken not only on SongTrivia2 but also in the security panel of the social login provider. Unused app permissions should be removed, recent sessions should be checked, and logouts should be performed from untrusted devices.\u003C\u002Fp> \u003Cp>Profile information on music and trivia platforms usually appears innocent; however, the combination of avatar, display name, username, and email can link different social accounts. If users also use the same image or nickname on their professional accounts, they should review profile pictures and public descriptions to reduce this link.\u003C\u002Fp>","SongTrivia2 Data Breach (291.7 Thousand Reported Records)","SongTrivia2 Data Breach. 291.7 Thousand reported records are reported. Reported data: Auth tokens, Avatars, Email addresses. Review the scope, risks, and…","\u002Fuploads\u002Flogo\u002Fsongtrivia2_io.webp",false,{"name":41,"sector":42,"country":16,"website":9,"websiteArchiveUrl":16,"websiteStatus":16,"websiteCheckedAt":12},"SongTrivia2","Entertainment"]