Breach directory
MySpace Data Breach (2008)
Around 360 million MySpace accounts, most with a weakly hashed password attached, surfaced for sale in May 2016. MySpace either never noticed the theft, years earlier, or never said.
- Accounts exposed
- 359,420,698
- When it happened
- 2008, approximate
- Added to Have I Been Pwned
- May 2016
- Data exposed
- Email addresses, usernames, passwords
- Passwords stored as
- SHA-1, unsalted, first 10 characters, lowercased
- Best estimate of the date
- Mid-2008 to early 2009, per Troy Hunt
- MySpace's own dating
- Before June 2013, via Troy Hunt
Breach data from Have I Been Pwned by Troy Hunt, licensed under CC BY 4.0.
Was your email address in the MySpace breach?
Type the address you used on MySpace, or any address you have used for years. Every breach holding it comes back, the MySpace record included.
What happened
The first anyone outside the company heard of the MySpace breach was a Motherboard report dated 27 May 2016: a seller using the alias Peace claimed to hold 360 million MySpace email addresses and passwords. Motherboard gave a data trading site the addresses of five people it knew and got the right password back for all five. MySpace did not answer requests for comment. Peace then listed the set on a criminal marketplace for six bitcoin, a few thousand dollars at 2016 prices.
Troy Hunt loaded all 359,420,698 unique addresses into Have I Been Pwned and published his dating analysis on 31 May 2016. With no timestamps in the dump he worked from the email providers: Yahoo addresses outnumbered Gmail five to one, which fits a userbase signed up before Gmail went mainstream. Readers who had kept their MySpace welcome emails were in the data; one who joined in December 2009 was not. His estimate was that MySpace was hacked sometime between mid-2008 and early 2009, and the exact date is unknown to this day.
MySpace’s one statement, noted in Troy Hunt’s update, dated the data to before a platform change on 11 June 2013 and said nothing about how long before.
In approximately 2008, MySpace suffered a data breach that exposed almost 360 million accounts. […] The exact breach date is unknown, but analysis of the data suggests it was 8 years before being made public.
What was exposed
The MySpace data breach left three fields per account: the email address, the MySpace username, and a SHA-1 hash of the password, with a second, older hash on about 68 million accounts according to Motherboard. Nothing else was in the set: no real name, no date of birth, no phone number.
Three fields is still worse than it sounds. Usernames are the handles people carried to other services, and the email address is the login on most of them, so each row is a ready-made pair to try elsewhere.
How the passwords were stored
MySpace stored SHA-1 hashes, unsalted, of only the first 10 characters of each password after lowercasing them. Together those three choices left the set close to readable.
SHA-1 was built for speed, so one modern card tries billions of guesses a second. Without a salt, identical passwords give identical hashes: crack “password1” once and every account using it falls with it. Truncation is the unusual part. A sixteen-character password with capitals and symbols became its first ten characters in lowercase before hashing, so the MySpace breach weakens even good passwords. Motherboard reported that the site holding the data expected to crack 98 or 99 percent of the hashes within a month. Assume yours was among them.
Timeline
Sometime in 2008, approximately
Data taken. No alert, no notice, no public record.
Before June 2013
MySpace's later statement, quoted by Troy Hunt, places the data before a platform change of 11 June 2013.
May 2016
Motherboard reports the sale on 27 May 2016; the set is listed for six bitcoin.
May 2016
Troy Hunt publishes his dating analysis on 31 May 2016 and Have I Been Pwned adds 359,420,698 addresses.
Disclosure lag
About eight years from theft to first public word, and MySpace users were never individually told.
What to do now
Start with the password. If any account still uses the MySpace password, or a longer one that begins with the same ten characters, change it there first: the hash covers that opening stretch whatever came after. Then the username. If your MySpace handle is your handle elsewhere, treat those accounts as linked to this email address and give each its own password and two-factor sign-in.
Phishing that mentions MySpace by name is unlikely after ten years; other breaches holding this address are not. Run the free LeakNix check to see which ones, and whether any exposed a password you still use.
Questions about the MySpace breach
When did the MySpace breach happen?
- Nobody knows the day. Have I Been Pwned dates it to approximately 2008, Troy Hunt's analysis puts it between mid-2008 and early 2009, and MySpace only said the data predates June 2013. It became public in May 2016.
Can the MySpace passwords be read?
- Treat them as readable. Hashes were unsalted SHA-1 of the first 10 lowercase characters, and the site holding the data told Motherboard it expected to crack 98 to 99 percent of them within a month of the 2016 sale.
Does the MySpace breach still matter?
- Only through reuse, which is enough. A MySpace login opens nothing today, but the same email and password pair tried on other sites is what these old sets are used for.
Related breaches
The MySpace data breach record here (359,420,698 accounts, 2008) is from Have I Been Pwned under CC BY 4.0, with no endorsement of LeakNix implied.
LeakNix