Skip to main content
  1. Home
  2. Computing
  3. News

New details reveal over 43M accounts were breached in 2012 Last.fm hack

Add as a preferred source on Google

The scale of a 2012 hack of music site Last.fm is now coming to light, revealing that more than 43 million accounts were affected.

LeakedSource, a data breach and hacking notification site, says it has obtained a copy of the hacked database. The site was originally breached in March 2012, which led the company to send out a password reset notification to its users, but it’s only now that the full scale of the hack is rearing its ugly head.

Recommended Videos

After analyzing and verifying the data, LeakedSource published its findings Thursday. It says the data includes usernames, hashed passwords, email addresses, and the date the user signed up to the site and/or the newsletter, as well as advertising data.

Perhaps most alarming is the hashed password data, which was secured with the MD5 hashing algorithm. MD5 has been considered outdated for a number of years. In 2012, the year of this hack, the original author of the algorithm wrote that it was no longer safe to us. As far back as 2005, a cryptographer wrote that MD5 was “broken”.

The case bears similarity to the Dropbox hack, details of which emerged Wednesday. Passwords were protected with SHA-1, another hashing algorithm that is becoming more and more outdated as computing power gets stronger.

In the case of Last.fm, LeakedSource was particularly alarmed by the use of MD5. “This algorithm is so insecure it took us two hours to crack and convert over 96 percent of them to visible passwords,” LeakedSource said, adding that it recently invested more into its own password-cracking capabilities for testing purposes.

The site also published a list of some of the most commonly used passwords it found and it doesn’t make for encouraging reading. The three passwords at the top of the list were “123456,” “password,” and “lastfm.”

Last.fm has yet to respond to the new details.

Jonathan Keane
Jonathan is a freelance technology journalist living in Dublin, Ireland. He's previously written for publications and sites…
The MacBook Air is running in short supply, despite a price hike
The memory crunch is now disrupting MacBook Air supplies
MacBook Air M5

For months, Apple seemed better protected from the memory crisis than most laptop makers. It had long-term supplier agreements, enormous purchasing power, and enough margin to absorb rising component costs. The situation has now caught up with its most popular laptop.

According to Bloomberg’s Mark Gurman, MacBook Air availability has tightened considerably across Apple’s retail network. Several configurations are showing delivery estimates stretching into late August, while some customized models may not arrive until September.

Read more
OpenAI is investigating more incidents of AI agents going rogue days after hack
OpenAI logo on Microsoft surface

It appears that the "AI agents going rogue" tale has more to it than what AI giants have revealed publicly so far. Merely days after OpenAI announced that its AI agents went rogue and hacked Hugging Face, Anthropic dropped a similar bombshell. Soon, it was discovered that not just one, but multiple services were compromised. Well, it seems there are even more layers to it.

Reuters reports that OpenAI has found more incidents of AI agents escaping their software containment environment during research. Citing sources with knowledge of the incident, the outlet notes that the AI agents didn't go beyond OpenAI's software environment and affect any external service.

Read more
AI is finding Apple security flaws faster than Apple can sort through them
Apple has limited how many bug reports researchers can keep open as AI tools produce both genuine Mac vulnerabilities and a flood of questionable submissions
Lighting, Architecture, Building

Apple has capped the number of security reports researchers can keep open at once after AI bug hunting put its review process under pressure, according to the Financial Times.

Some submissions describe hallucinated or purely theoretical risks. Others uncover vulnerabilities serious enough to require patches. Bynario told the FT that it found more than 50 possible macOS flaws in three weeks, including a privilege-escalation chain that could give an attacker full control of a Mac.

Read more