LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

Recent Breaches › 8tracks Data Breach (2017)

CRITICAL severityConfirmedHow we verify

8tracks Data Breach (2017): What Was Exposed & What To Do

RBRecent Breaches Breach Intelligence·June 27, 2017

SourceBreach data provided in part by Have I Been Pwned, used under CC BY 4.0.

8tracks Data Breach (2017)

Reported June 27, 2017. Approximately 18.0M people affected.

CRITICAL
Severity
18.0M
People affected
2
Data types exposed
June 27, 2017
Disclosed
ShareXLinkedInFacebookRedditWhatsAppTelegram

The 8tracks Data Breach (2017) (reported June 27, 2017) exposed Email addresses and Passwords belonging to roughly 18.0M people. If you have an account with them, your information may now be circulating on the open web and with data brokers. Here’s exactly what happened, how to check if you were affected, and what to do next.

Severity & verification
CRITICAL severityConfirmed
Account credentials exposed.
Corroborated by an official disclosure or a verified breach feed.
Was your email in the 8tracks Data Breach (2017) breach?
18.0M accounts were exposed here. See if yours is one — and every other breach it’s in. 15-sec check, no card.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

In June 2017, the playlists service 8tracks disclosed a data breach that affected 18 million accounts. The incident exposed email addresses and passwords, with the company stating that the attack vector was an employee’s GitHub account that lacked two-factor authentication. Salted SHA-1 password hashes were included for users who had not signed up through Google or Facebook. The data later appeared in public breach repositories, including Have I Been Pwned.

People whose accounts were involved now face the possibility that their email addresses and password hashes are available to anyone who obtains the data set. Because many users reuse passwords across services, the exposure can extend beyond 8tracks itself.

Breaking down the breach

The breach was reported on 27 June 2017. It involved 18 million accounts. The company’s disclosure identified the initial point of compromise as an employee GitHub account that was not protected by two-factor authentication. Password data consisted of salted SHA-1 hashes for users who registered directly rather than through Google or Facebook authentication. A white-hat researcher later supplied a version of the data containing nearly 8 million unique email addresses to Have I Been Pwned; the full set of 18 million records subsequently became available.

How a breach like this happens

Incidents that begin with an employee’s external account often follow a common pattern. An attacker obtains credentials for a service the employee uses, such as a code repository. When that account is not protected by two-factor authentication, the attacker can access any repositories or files the employee has permission to view. If those files contain production credentials or database exports, the attacker can move from the external account into the organisation’s internal systems and extract user data.

Who is 8tracks?

8tracks operates an online music-playlists service. Users create and share playlists, which requires the platform to store account details including email addresses and authentication data. Services of this type routinely hold information that can be used both to contact users and to attempt access to their accounts on other sites when passwords are reused.

What was likely exposed

The disclosed data types are email addresses and passwords. For users who did not sign in with Google or Facebook, the passwords were stored as salted SHA-1 hashes. The exact contents of every record remain unconfirmed beyond the categories named in the disclosure and the partial data set supplied to breach-notification services. No other categories of personal information are stated in the available facts.

Why it matters

Email addresses combined with password hashes allow attackers to test the same credentials on other websites. When users have reused passwords, this can lead to unauthorised access to additional accounts. For the organisation, the incident highlights the risk that a single external account without multi-factor protection can serve as an entry point to large volumes of user data.

If your data was in this breach

Change the password on your 8tracks account and on any other service where you used the same password. Enable two-factor authentication wherever it is available. You can run a free exposure scan of your email address against known breach data sets to check whether your information appears in this or other incidents.

AICompiled with AI assistance from public sources and published under our editorial standards.

Editorial & sourcing policy
Recent Breaches is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data, and we do not hold the data claimed in leak-site listings. Incidents are compiled from publicly accessible sources and threat-intelligence platforms and are reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — write to support@galaxywarden.com or press@recentbreaches.com.
Check if you’re exposed →

How this breach connects

Company

Method

Company8tracks security record
73/100
DoxxScan™ · Moderate doxx risk
C- 64Below-average record

1 reported incident on record.

See 8tracks’s full breach history →

More recent breaches

2fast4u Data Breach (2017)December 20, 2017Synthient Credential Stuffing Threat Data Data Breach (2025)April 11, 20251win Data Breach (2024)November 2, 2024Flat Earth Sun, Moon and Zodiac App Data Breach (2024)October 15, 2024

Latest breaches

Read GalaxyWarden’s full analysis of the 8tracks Data Breach (2017) →

Verified breach. Breach data provided in part by Have I Been Pwned, used under CC BY 4.0.

Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.

Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.

ShareXLinkedInFacebookRedditWhatsAppTelegram