Data of over 200 million Deezer customers stolen, leaks on hacking discussion board • Graham Cluley

0
270

[ad_1]

Data of over 200 million Deezer users leaks on hacking forum

Music-streaming service Deezer has owned up to a knowledge breach, after hackers managed to steal the info of over 200 million of its customers.

The information, which seems to have been stolen from certainly one of Deezer’s third-party service suppliers in 2019, consists of:

  • First and final names
  • Dates of start
  • Email addresses
  • IP addresses
  • Gender
  • Location information (City and Country)
  • Join date
  • User ID

According to RestorePrivacy which first reported on the breach, the hacker launched a pattern 5 million stolen information on a well known hacking discussion board, claiming to have a 60GB stash of stolen information, together with 228 million e-mail addresses:

Today im promoting the data of over 200+ million Deezer.com customers from 2019 (particularly earlier than september-october of 2019). It consists of Users CSV which is a 60gb file with 257,829,454 information, of these information there are approx 228 million non anonymized distinctive emails. A CSV containing logged person classes (IP Address and system). Profiles CS, and a folder named ultimate containing 106 CV’s. Source continues to be unclear but it surely looks like Deezer employed a 3rd occasion information evaluation firm to investigate their customers. Ill look forward to deezer to verify the place this got here from lmao. First purchaser additionally recieves entry to the place this got here from (theres some additional stuff within the supply of this).

Deezer printed a assist advisory concerning the breach in November, shortly after the hacker’s submit.

Deezer describes the leaked information as “non-sensitive information”, and claims that no passwords or cost particulars have been uncovered.

Non-sensitive? Hmm. At the very least the e-mail addresses and different data could possibly be used to create convicing phishing emails, and maybe be abused by fraudsters to extract additional particulars from Deezer customers.

And I, for one, am disenchanted to haven’t obtain any notification concerning the breach from Deezer.

EmailSign as much as our publication
Security information, recommendation, and ideas.

Back within the mists of time (2014), I had a Deezer account. I’d fully forgotten about it, however managed to log again into Deezer at present and located my account was nonetheless energetic.

Thankfully I haven’t been paying a subscription all this time, however I’m disgruntled that Deezer hasn’t reached out to affected customers to tell them that the breach has occurred. Instead, the primary I knew about it was after I acquired a notification from Troy Hunt’s Have I Been Pwned mission.

Have I Been Pwned notification of Deezer data breach
Have I Been Pwned notification of Deezer information breach

Naturally I’ve modified my password as a precaution despite the fact that I haven’t used Deezer’s providers for nearly 10 years. When I get the prospect, I’ll look into how I can delete my account fully.

You could want to think about doing the identical in the event you don’t have any use for Deezer, or on the very least change your password.

As at all times, make it a robust one which’s laborious to crack, and be sure that you’re not utilizing it anyplace else on the web.

Found this text fascinating? Follow Graham Cluley on Twitter or Mastodon to learn extra of the unique content material we submit.


Graham Cluley is a veteran of the anti-virus business having labored for numerous safety corporations for the reason that early Nineties when he wrote the primary ever model of Dr Solomon’s Anti-Virus Toolkit for Windows. Now an unbiased safety analyst, he usually makes media appearances and is an international public speaker on the subject of laptop safety, hackers, and on-line privateness.
Follow him on Twitter at @gcluley, on Mastodon at @[email protected], or drop him an e-mail.

LEAVE A REPLY

Please enter your comment!
Please enter your name here