Last.fm Data Breach (2012): What Was Exposed & What To Do
SourceBreach data provided in part by Have I Been Pwned, used under CC BY 4.0.
The Last.fm Data Breach (2012) (reported March 22, 2012) exposed Email addresses, Passwords, Usernames and Website activity belonging to roughly 37.2M people. If you have an account with them, your information may now be circulating on the open web and with data brokers. Here’s exactly what happened, how to check if you were affected, and what to do next.
Inside the incident
Public records indicate that the intrusion occurred in March 2012. Last.fm confirmed awareness of unauthorised access that year, but the volume of records involved was not established until the data set was released online in September 2016. The material included 37 million unique email addresses along with corresponding usernames and passwords held as unsalted MD5 hashes. Website activity logs were also part of the exposed set. No further technical details about the method of entry or the duration of access have been disclosed in available reporting.
How a breach like this happens
Incidents involving the extraction of user account data from online services commonly begin with an attacker obtaining entry to internal systems through vulnerabilities in web applications, weak authentication controls, or compromised administrative credentials. Once inside, the attacker can locate and copy databases that store account information. When passwords are protected only by unsalted cryptographic hashes, the contents become easier to process offline in an attempt to recover the original values. The time between the initial intrusion and public awareness can vary considerably when the organisation detects the activity but does not immediately determine its full scope.
Who is Last.fm?
Last.fm operates as a music discovery and streaming platform that requires users to create accounts to track listening habits, receive recommendations, and interact with other listeners. Services of this kind routinely collect email addresses for account management and communication, usernames for identification, passwords for authentication, and activity data that records user behaviour on the site. A compromise at such a service therefore touches both direct account credentials and a detailed record of individual listening patterns accumulated over time.
The information in question
The records released in 2016 contained email addresses, usernames, passwords stored as unsalted MD5 hashes, and website activity information. The exact number of unique accounts tied to these records is stated as 37 million in the available data, although some summaries have referred to a larger total of accounts. No additional categories of information, such as payment details or full names, are confirmed in the published facts. Organisations in this sector typically hold the data types listed above, but the precise contents of any unreleased portions of the data set remain unconfirmed.
Why it matters
Email addresses and usernames can be used to target individuals with further attempts to gain access to other online accounts, especially where the same credentials have been reused. Passwords stored as unsalted MD5 hashes are more susceptible to recovery than those protected by stronger methods, increasing the chance that recovered credentials could be tested against other services. Activity logs may reveal patterns of behaviour that some users prefer to keep private. For the organisation, the delayed public disclosure of the full scale meant that users could not take protective steps for several years after the original intrusion.
What to do if you're exposed
Individuals who believe their Last.fm account may be involved should change the password on that account and on any other service where the same password was used. Enabling two-factor authentication where available adds a further layer of protection. Monitoring email accounts for unusual login attempts or unsolicited messages is a prudent step. Readers can run a free exposure scan of their email address against known breach data sets to check whether their information appears in publicly reported incidents.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
Heroes of Newerth Data Breach (2012)BookCrossing Data Breach (2012)Netlog Data Breach (2012)Lookbook Data Breach (2012)Latest breaches
Read GalaxyWarden’s full analysis of the Last.fm Data Breach (2012) →
Verified breach. Breach data provided in part by Have I Been Pwned, used under CC BY 4.0.
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.