Time confirms Myspace breach limited to a portion of login data created before June 11, 2013; LeakedSource says over 360M accounts compromised
You might not have thought of - much less visited - Myspace in years. (Yes, it's still around. Time, Inc. acquired itand other properties when it bought Viant earlier this year.)
Context & Ripple Effects
Two days before this confirmation, the same seller who dumped LinkedIn's 117M-record database put up a claim of 360M Myspace emails with passwords, and LeakedSource began indexing them. Time, Inc. had only just absorbed Myspace through its Viant acquisition, so it inherited the breach along with the property.
Time's statement narrows the blast radius to login records created before June 11, 2013 — but that cutoff still covers most of the site's peak-era user base, and the Last.fm dump showed how quickly weakly hashed passwords from that era crack once they hit an indexing service.
First-order effects
- Anyone whose Myspace account predates June 2013 has credentials in circulation, and Time inherits the cleanup: forced resets and notification for a user base that largely forgot the site existed.
- LeakedSource gains a searchable index of over 360M Myspace logins, making the data queryable rather than just for-sale.
Second-order effects
- Password reuse turns the dump into a liability beyond Myspace: credentials cracked there can unlock accounts on services those lapsed users still actively use.
- The seller's playbook — recycle a proven buyer like the LinkedIn database purchaser across multiple old targets — signals more legacy-platform dumps are being shopped.
Third-order effects
- Acquirers of aging web properties now price in dormant credential databases as a standing liability, since a decade-old breach can surface on a new owner's watch — a pattern Myspace repeated when its account recovery form later let anyone with basic profile details hijack accounts.
- Breach disclosure is shifting from the breached company's announcement to third-party indexes confirming scale first, forcing owners into reactive confirmation rather than proactive disclosure.
The trend: Credentials from dormant early-social-web platforms are becoming a recurring commodity in the breach-data market, with acquirers and indexing services — not the original operators — setting the terms of disclosure.