8tracks Data Breach (2017): What Was Exposed & What To Do
SourceBreach data provided in part by Have I Been Pwned, used under CC BY 4.0.
The 8tracks Data Breach (2017) (reported June 27, 2017) exposed Email addresses and Passwords belonging to roughly 18.0M people. If you have an account with them, your information may now be circulating on the open web and with data brokers. Here’s exactly what happened, how to check if you were affected, and what to do next.
In June 2017, the playlists service 8tracks disclosed a data breach that affected 18 million accounts. The incident exposed email addresses and passwords, with the company stating that the attack vector was an employee’s GitHub account that lacked two-factor authentication. Salted SHA-1 password hashes were included for users who had not signed up through Google or Facebook. The data later appeared in public breach repositories, including Have I Been Pwned.
People whose accounts were involved now face the possibility that their email addresses and password hashes are available to anyone who obtains the data set. Because many users reuse passwords across services, the exposure can extend beyond 8tracks itself.
Breaking down the breach
The breach was reported on 27 June 2017. It involved 18 million accounts. The company’s disclosure identified the initial point of compromise as an employee GitHub account that was not protected by two-factor authentication. Password data consisted of salted SHA-1 hashes for users who registered directly rather than through Google or Facebook authentication. A white-hat researcher later supplied a version of the data containing nearly 8 million unique email addresses to Have I Been Pwned; the full set of 18 million records subsequently became available.
How a breach like this happens
Incidents that begin with an employee’s external account often follow a common pattern. An attacker obtains credentials for a service the employee uses, such as a code repository. When that account is not protected by two-factor authentication, the attacker can access any repositories or files the employee has permission to view. If those files contain production credentials or database exports, the attacker can move from the external account into the organisation’s internal systems and extract user data.
Who is 8tracks?
8tracks operates an online music-playlists service. Users create and share playlists, which requires the platform to store account details including email addresses and authentication data. Services of this type routinely hold information that can be used both to contact users and to attempt access to their accounts on other sites when passwords are reused.
What was likely exposed
The disclosed data types are email addresses and passwords. For users who did not sign in with Google or Facebook, the passwords were stored as salted SHA-1 hashes. The exact contents of every record remain unconfirmed beyond the categories named in the disclosure and the partial data set supplied to breach-notification services. No other categories of personal information are stated in the available facts.
Why it matters
Email addresses combined with password hashes allow attackers to test the same credentials on other websites. When users have reused passwords, this can lead to unauthorised access to additional accounts. For the organisation, the incident highlights the risk that a single external account without multi-factor protection can serve as an entry point to large volumes of user data.
If your data was in this breach
Change the password on your 8tracks account and on any other service where you used the same password. Enable two-factor authentication wherever it is available. You can run a free exposure scan of your email address against known breach data sets to check whether your information appears in this or other incidents.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
2fast4u Data Breach (2017)Synthient Credential Stuffing Threat Data Data Breach (2025)1win Data Breach (2024)Flat Earth Sun, Moon and Zodiac App Data Breach (2024)Latest breaches
Read GalaxyWarden’s full analysis of the 8tracks Data Breach (2017) →
Verified breach. Breach data provided in part by Have I Been Pwned, used under CC BY 4.0.
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.