Skip to content
Data breachResolved

Deezer data breach (2019)

A 2019 snapshot of Deezer user data, retained by a former third-party partner in violation of its contract, was leaked in November 2022 and exposed roughly 229 million records — including names, emails, dates of birth, and locations. No passwords or payment data were affected.

Victim
Deezer
records
229.0M
users
229.0M

In November 2022, a sprawling dataset of Deezer user records surfaced on a hacking forum — but the data itself dated to 2019, having been retained by a former third-party partner long after it should have been destroyed. The leak ultimately exposed roughly 229 million records.

What happened

The Paris-based music-streaming service Deezer had shared user data with a third-party service provider as part of normal operations around 2019. Deezer ended that relationship in 2020, and under the terms of their contract the provider was obligated to destroy the data it held.

Instead, the provider retained a 2019 snapshot of Deezer's user base. On 6 November 2022, a user of a well-known breach forum posted a roughly 60 GB CSV file containing 257,829,454 records drawn from this snapshot. Deezer later confirmed the incident was a third-party breach, emphasizing that its own infrastructure had not been compromised and that the provider had breached its contractual obligations by keeping the data.

Data exposed

Because the records came from a 2019 snapshot, the exposed fields reflected the profile data Deezer held at that time:

  • Email addresses
  • First and last names
  • Dates of birth
  • Gender
  • Location data (city and country)
  • User ID and account registration date

Crucially, Deezer stated that no passwords and no payment information were included in the dataset. When the breach was loaded into Have I Been Pwned, it was de-duplicated to 229,037,936 unique email addresses.

Impact

Even without credentials or financial data, the combination of name, email, date of birth, and location is highly useful for targeted phishing, identity-correlation, and social-engineering campaigns. The breach drew scrutiny under the EU's GDPR, given Deezer's status as a French company and the volume of European users affected. Deezer notified regulators and affected users and reiterated that its core systems remained secure.

Why it matters

The Deezer incident is a textbook third-party / supply-chain data exposure: the breach did not originate inside Deezer's own environment but with a vendor that failed to delete data after the engagement ended. It underscores that data-protection obligations do not stop at a company's perimeter — contractual data-destruction clauses are only as good as the partner's compliance, and a single non-compliant vendor can produce a nine-figure breach years after the business relationship ends. It is a recurring lesson for any organization that shares personal data with processors and subcontractors.

Timeline

  1. A third-party service provider takes a snapshot of Deezer user data while working with the streaming service.

  2. Deezer ends its relationship with the provider; under contract, the provider was required to destroy the retained data.

  3. A ~60 GB CSV file containing 257.8 million records is posted to a well-known breach forum.

  4. Researchers and outlets including Music Business Worldwide report the exposure of over 220 million Deezer users.

  5. Deezer confirms a third-party breach, stating no passwords or payment data were compromised and that the provider had retained data in breach of contract.

  6. The dataset is loaded into Have I Been Pwned at 229,037,936 unique email addresses, letting users check exposure.

Sources

  1. haveibeenpwned.comhttps://haveibeenpwned.com/Breach/Deezer
  2. support.deezer.comhttps://support.deezer.com/hc/en-gb/articles/7726141292317-Third-Party-Data-Breach
  3. musicbusinessworldwide.comhttps://www.musicbusinessworldwide.com/deezer-admits-data-breach-that-potentially-exposed-over-220-million-users-info/
  4. purplesec.ushttps://purplesec.us/breach-report/deezer-data-leak-228-million-users/

Related incidents

Data breachOngoing

1,528 contacts at Nature & Cie, claimed leak

In late May 2026, a B2B commercial database attributed to French organic-food distributor Nature & Cie surfaced on a cybercriminal forum, exposing roughly 5,635 stores, over 1,500 professional contacts and around 1,500 sales-visit reports covering Biocoop, Naturalia and La Vie Claire partners.

Victim
Nature & Cie
Records
1.5K