Skip to main content

New details reveal over 43M accounts were breached in 2012 Last.fm hack

last fm 2012 hack 43 million accounts
Lorenzo Massacci/Flickr
The scale of a 2012 hack of music site Last.fm is now coming to light, revealing that more than 43 million accounts were affected.

LeakedSource, a data breach and hacking notification site, says it has obtained a copy of the hacked database. The site was originally breached in March 2012, which led the company to send out a password reset notification to its users, but it’s only now that the full scale of the hack is rearing its ugly head.

After analyzing and verifying the data, LeakedSource published its findings Thursday. It says the data includes usernames, hashed passwords, email addresses, and the date the user signed up to the site and/or the newsletter, as well as advertising data.

Perhaps most alarming is the hashed password data, which was secured with the MD5 hashing algorithm. MD5 has been considered outdated for a number of years. In 2012, the year of this hack, the original author of the algorithm wrote that it was no longer safe to us. As far back as 2005, a cryptographer wrote that MD5 was “broken”.

The case bears similarity to the Dropbox hack, details of which emerged Wednesday. Passwords were protected with SHA-1, another hashing algorithm that is becoming more and more outdated as computing power gets stronger.

In the case of Last.fm, LeakedSource was particularly alarmed by the use of MD5. “This algorithm is so insecure it took us two hours to crack and convert over 96 percent of them to visible passwords,” LeakedSource said, adding that it recently invested more into its own password-cracking capabilities for testing purposes.

The site also published a list of some of the most commonly used passwords it found and it doesn’t make for encouraging reading. The three passwords at the top of the list were “123456,” “password,” and “lastfm.”

Last.fm has yet to respond to the new details.

Jonathan Keane
Former Digital Trends Contributor
Jonathan is a freelance technology journalist living in Dublin, Ireland. He's previously written for publications and sites…
4 CPUs you should buy instead of the Ryzen 7 7800X3D
AMD Ryzen 7 7800X3D sitting on a motherboard.

The Ryzen 7 7800X3D is one of the best gaming processors you can buy, and it's easy to see why. It's easily the fastest gaming CPU on the market, it's reasonably priced, and it's available on a platform that AMD says it will support for several years. But it's not the right chip for everyone.

Although the Ryzen 7 7800X3D ticks all the right boxes, there are several alternatives available. Some are cheaper while still offering great performance, while others are more powerful in applications outside of gaming. The Ryzen 7 7800X3D is a great CPU, but if you want to do a little more shopping, these are the other processors you should consider.
AMD Ryzen 7 5800X3D

Read more
Even the new mid-tier Snapdragon X Plus beats Apple’s M3
A photo of the Snapdragon X Plus CPU in the die

You might have already heard of the Snapdragon X Elite, the upcoming chips from Qualcomm that everyone's excited about. They're not out yet, but Qualcomm is already announcing another configuration to live alongside it: the Snapdragon X Plus.

The Snapdragon X Plus is pretty similar to the flagship Snapdragon X Elite in terms of everyday performance but, as a new chip tier, aims to bring AI capabilities to a wider portfolio of ARM-powered laptops. To be clear, though, this one is a step down from the flagship Snapdragon X Elite, in the same way that an Intel Core Ultra 7 is a step down from Core Ultra 9.

Read more
Gigabyte just confirmed AMD’s Ryzen 9000 CPUs
Pads on the AMD Ryzen 7 7800X3D.

Gigabyte spoiled AMD's surprise a bit by confirming the company's next-gen CPUs. In a press release announcing a new BIOS for X670, B650, and A620 motherboards, Gigabyte not only confirmed that support has been added for next-gen AMD CPUs, but specifically referred to them as "AMD Ryzen 9000 series processors."

We've already seen MSI and Asus add support for next-gen AMD CPUs through BIOS updates, but neither of them called the CPUs Ryzen 9000. They didn't put out a dedicated press release for the updates, either. It should go without saying, but we don't often see a press release for new BIOS versions, suggesting Gigabyte wanted to make a splash with its support.

Read more