Hacker behind LinkedIn's 117M e-mail database claims to have 360M Myspace user emails with passwords
MySpace was hacked. LeakedSource has obtained … AJ Dellinger / The Daily Dot : MySpace may have been hacked and never told its users about it Tyler Lee / Ubergizmo : Hacker Tries To Sell 427 Million Stolen MySpace Passwords Catalin Cimpanu / Softpedia News : MySpace Data Breach Exposes Passwords for 427 Million Users Kate Cox / Consumerist : Over 427M Hacked Myspace Passwords Set Loose Online Jack Danahy / Xconomy : 117M LinkedIn Passwords for Sale: What You Should Do Now Office of Inadequate Security : Hackers Claim to Have a Stunning 427 Million Myspace Passwords Gordon Hunt / Silicon Republic : Reddit resets 100,000 passwords amid security worries Tweets: Yan / @bcrypt : haha good thing my myspace password was the same as my LinkedIn password http://motherboard.vice.com/ ... Lorenzo Franceschi-B / @lorenzofb : If the total number of MySpace users and passwords check out, this is perhaps the largest data breach ever. http://motherboard.vice.com/ ... Lorenzo Franceschi-B / @lorenzofb : We couldn't verify total number, but we tested five MySpace accounts and the passwords checked out. http://motherboard.vice.com/ ... @motherboard : First LinkedIn, now this: hackers claim to have 427 MILLION MySpace passwords http://motherboard.vice.com/ ... http://twitter.com/...
Context & Ripple Effects
Days after a seller put LinkedIn's 117M stolen emails and passwords up for sale on a dark web marketplace — prompting LinkedIn to contact affected users over a 2012 breach — the same actor is claiming an even larger haul: 360M Myspace user email/password pairs, with LeakedSource reporting it has obtained the data.
Two details sharpen the story: reports suggest Myspace was hacked without telling its users, and Time later confirmed the breach covered only login data created before June 11, 2013. That makes this part of a pattern alongside the 2012 Last.fm hack, where 96% of hashed passwords fell within two hours — old breaches resurfacing as sellable inventory.
First-order effects
- Myspace users whose accounts predate June 2013 have their email-and-password combinations exposed for sale, and because the company apparently never notified them, most are learning about it from the marketplace listing rather than from Myspace itself.
- LeakedSource gains another mega-dump for its searchable breach index, extending the role it already plays around the LinkedIn cache.
Second-order effects
- Password reuse turns this into every other service's problem: the corpus already shows Reddit resetting 100,000 passwords over leaked-credential concerns, and services with Myspace-era users face the same forced resets and fraud screening.
- As Ars Technica explains of the full LinkedIn dump, large plaintext or weakly-hashed caches don't just expose their own users — they speed up cracking of hashed passwords in any future breach, lowering the value of weak hashing schemes everywhere.
Third-order effects
- If decade-old databases keep surfacing as sellable assets, silent non-disclosure stops being viable: companies holding stale, poorly hashed login data inherit a standing obligation to notify users years after the fact, or absorb the reputational cost when a seller does it for them.
- The economics point toward credential dumps consolidating into a brokered market — one seller, multiple platform-scale caches — which pushes defenders toward assuming breach rather than preventing any single leak.
The trend: Breaches from the early-2010s are resurfacing as monetizable dark-web inventory, forcing retroactive disclosure and making weakly stored legacy passwords a persistent liability across the industry.