In the 2012 Last.fm hack, details of 43.57M accounts were stolen; 96% of hashed passwords were able to be cracked within 2 hours
LeakedSource has exposed every single mega breach of 2016 including LinkedIn, MySpace, and VK.com but because we are the most effective breach notification service in the world, we're back with more.
Context & Ripple Effects
LeakedSource has spent 2016 publishing the year's mega-breach troves — LinkedIn, MySpace, and VK.com among them — and now adds Last.fm to the pile. The Last.fm data dates to 2012, the same vintage as the 117M LinkedIn credentials later offered on a dark web marketplace, and the pattern is identical: an old breach resurfaces years later through broker channels rather than from the company itself.
The technical detail is what makes this entry notable: 96% of the hashed passwords fell within two hours, meaning Last.fm's 2012-era hashing was effectively no barrier at all once the database leaked. That mirrors LeakBase's finding on the Taringa breach, where nearly 94% of hashed passwords were cracked — weak digest schemes are the common thread across these dumps.
First-order effects
- Last.fm users whose credentials appear in the dump face immediate account-takeover risk wherever they reused those passwords, and the service faces a forced wave of resets and notifications like the ones LinkedIn ran when its own 2012 cache surfaced.
Second-order effects
- The string of 2016 publications — LeakedSource's LinkedIn, MySpace, and VK.com drops plus the hacker's claimed 360M MySpace emails — turns legacy password storage into a live liability for every social platform still running fast hashes on old accounts, pressuring them to audit and re-hash pre-2014 credentials.
Third-order effects
- If brokers keep monetizing decade-old caches, breach exposure stops being a point-in-time event and becomes a recurring revenue line for sellers — pushing the industry toward deliberately slow hashing (bcrypt-class schemes) and toward paid breach-notification services as a standing product rather than an emergency response.
The trend: Breaches from the early-2010s are being recycled into a broker-driven market years after the fact, converting weak legacy password hashing into a long-tail liability for consumer platforms.