Last.fm data breach (2012)
The music platform Last.fm was hacked in March 2012, exposing more than 43 million accounts with usernames, email addresses and unsalted MD5 password hashes; over 96% of passwords were cracked within hours once the data surfaced in 2016.
- Victim
- Last.fm
- records
- 37.2M
- users
- 43.6M
In March 2012, the UK-based music-streaming and scrobbling service Last.fm was hacked and its user database stolen. Last.fm warned users of a possible incident at the time, but the full scale β more than 43 million accounts β only became public in September 2016, when the dataset surfaced as part of that year's wave of historical mega breaches.
What happened
The intrusion occurred on or around 22 March 2012. On 7 June 2012, Last.fm posted a security notice urging users to change their passwords "as a precautionary measure" following a possible breach, but it did not quantify the exposure. For four years the incident was treated as a minor episode.
That assessment collapsed in September 2016, when the breach-notification service LeakedSource obtained a copy of the database and shared its analysis with TechCrunch. The dataset contained well over 43 million records, dwarfing earlier assumptions about the breach's size.
What was exposed
Each record included a username, email address, password, join date, and assorted internal Last.fm service data (such as newsletter and account metadata). Critically, the passwords were stored as unsalted MD5 hashes β a fast, weak scheme with no per-user salt.
The consequences were stark. Because the hashes were unsalted MD5, researchers reported cracking over 96% of the passwords in roughly two hours. The single most common password recovered was "123456," underscoring both the weak hashing and weak user password choices.
Impact
- 43,570,999 accounts exposed (Have I Been Pwned indexes 37,217,682 unique email addresses from the set).
- Near-total password recovery thanks to unsalted MD5, exposing users to credential stuffing wherever they had reused the same password.
- Email addresses and usernames fed downstream phishing and spam.
Why it matters
Last.fm is a textbook example of why unsalted MD5 was already considered unacceptable for password storage by 2012, and of the danger of under-disclosing breach scope. The contrast with Tumblr β breached the same era but using salted SHA-1 β is instructive: similar attacks produced wildly different outcomes for users based on hashing design alone. The four-year gap between the 2012 incident and the 2016 revelation also meant millions of reused passwords remained exploitable long after the original theft.
Timeline
Attackers compromise Last.fm and exfiltrate the user database, including usernames, email addresses and unsalted MD5 password hashes.
Last.fm publicly warns users of a possible breach and advises immediate password changes, but does not disclose the full scale.
LeakedSource and TechCrunch reveal the 2012 dataset contains over 43 million accounts; the full extent of the breach becomes public.
Researchers crack over 96% of the unsalted MD5 password hashes in roughly two hours, with '123456' the most common password.
Sources
- haveibeenpwned.comhttps://haveibeenpwned.com/Breach/Lastfm
- techcrunch.comhttps://techcrunch.com/2016/09/01/43-million-passwords-hacked-in-last-fm-breach/
- securityweek.comhttps://www.securityweek.com/43-million-lastfm-accounts-stolen-2012-breach/
- csoonline.comhttps://www.csoonline.com/article/557747/lastfm-breach-from-2012-affected-43-million-users.html
- news.softpedia.comhttps://news.softpedia.com/news/data-of-43-million-users-stolen-during-2012-last-fm-data-breach-507830.shtml