LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

Recent Breaches › Last.fm Data Breach (2012)

CRITICAL severityConfirmedHow we verify

Last.fm Data Breach (2012): What Was Exposed & What To Do

RBRecent Breaches Breach Intelligence·March 22, 2012

SourceBreach data provided in part by Have I Been Pwned, used under CC BY 4.0.

Last.fm Data Breach (2012)

Reported March 22, 2012. Approximately 37.2M people affected.

CRITICAL
Severity
37.2M
People affected
4
Data types exposed
March 22, 2012
Disclosed
ShareXLinkedInFacebookRedditWhatsAppTelegram

The Last.fm Data Breach (2012) (reported March 22, 2012) exposed Email addresses, Passwords, Usernames and Website activity belonging to roughly 37.2M people. If you have an account with them, your information may now be circulating on the open web and with data brokers. Here’s exactly what happened, how to check if you were affected, and what to do next.

Severity & verification
CRITICAL severityConfirmed
Account credentials exposed.
Corroborated by an official disclosure or a verified breach feed.
Was your email in the Last.fm Data Breach (2012) breach?
37.2M accounts were exposed here. See if yours is one — and every other breach it’s in. 15-sec check, no card.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

In March 2012, the music website Last.fm experienced a security incident in which data associated with user accounts was taken from its systems. The organisation later stated that it had identified an intrusion at the time, yet the extent of the data exposure remained unclear until the material appeared publicly in September 2016. Approximately 37.2 million individuals were affected according to the records now available. The incident left email addresses, usernames, passwords stored as unsalted MD5 hashes, and records of website activity outside the control of the service for an extended period.

Inside the incident

Public records indicate that the intrusion occurred in March 2012. Last.fm confirmed awareness of unauthorised access that year, but the volume of records involved was not established until the data set was released online in September 2016. The material included 37 million unique email addresses along with corresponding usernames and passwords held as unsalted MD5 hashes. Website activity logs were also part of the exposed set. No further technical details about the method of entry or the duration of access have been disclosed in available reporting.

How a breach like this happens

Incidents involving the extraction of user account data from online services commonly begin with an attacker obtaining entry to internal systems through vulnerabilities in web applications, weak authentication controls, or compromised administrative credentials. Once inside, the attacker can locate and copy databases that store account information. When passwords are protected only by unsalted cryptographic hashes, the contents become easier to process offline in an attempt to recover the original values. The time between the initial intrusion and public awareness can vary considerably when the organisation detects the activity but does not immediately determine its full scope.

Who is Last.fm?

Last.fm operates as a music discovery and streaming platform that requires users to create accounts to track listening habits, receive recommendations, and interact with other listeners. Services of this kind routinely collect email addresses for account management and communication, usernames for identification, passwords for authentication, and activity data that records user behaviour on the site. A compromise at such a service therefore touches both direct account credentials and a detailed record of individual listening patterns accumulated over time.

The information in question

The records released in 2016 contained email addresses, usernames, passwords stored as unsalted MD5 hashes, and website activity information. The exact number of unique accounts tied to these records is stated as 37 million in the available data, although some summaries have referred to a larger total of accounts. No additional categories of information, such as payment details or full names, are confirmed in the published facts. Organisations in this sector typically hold the data types listed above, but the precise contents of any unreleased portions of the data set remain unconfirmed.

Why it matters

Email addresses and usernames can be used to target individuals with further attempts to gain access to other online accounts, especially where the same credentials have been reused. Passwords stored as unsalted MD5 hashes are more susceptible to recovery than those protected by stronger methods, increasing the chance that recovered credentials could be tested against other services. Activity logs may reveal patterns of behaviour that some users prefer to keep private. For the organisation, the delayed public disclosure of the full scale meant that users could not take protective steps for several years after the original intrusion.

What to do if you're exposed

Individuals who believe their Last.fm account may be involved should change the password on that account and on any other service where the same password was used. Enabling two-factor authentication where available adds a further layer of protection. Monitoring email accounts for unusual login attempts or unsolicited messages is a prudent step. Readers can run a free exposure scan of their email address against known breach data sets to check whether their information appears in publicly reported incidents.

AICompiled with AI assistance from public sources and published under our editorial standards.

Editorial & sourcing policy
Recent Breaches is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data, and we do not hold the data claimed in leak-site listings. Incidents are compiled from publicly accessible sources and threat-intelligence platforms and are reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — write to support@galaxywarden.com or press@recentbreaches.com.
Check if you’re exposed →

How this breach connects

Company

Method

CompanyLast.fm security record
73/100
DoxxScan™ · Moderate doxx risk
C- 64Below-average record

1 reported incident on record.

See Last.fm’s full breach history →

More recent breaches

Heroes of Newerth Data Breach (2012)December 17, 2012BookCrossing Data Breach (2012)November 5, 2012Netlog Data Breach (2012)November 1, 2012Lookbook Data Breach (2012)August 24, 2012

Latest breaches

Read GalaxyWarden’s full analysis of the Last.fm Data Breach (2012) →

Verified breach. Breach data provided in part by Have I Been Pwned, used under CC BY 4.0.

Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.

Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.

ShareXLinkedInFacebookRedditWhatsAppTelegram