In the 2012 Last.fm hack, details of 43.57M accounts were stolen; 96% of hashed passwords were able to be cracked within 2 hours
LeakedSource :
Context & Ripple Effects
LeakedSource's publication of the 2012 Last.fm breach — 43.57M accounts with 96% of hashed passwords cracked within two hours — is part of a wave of long-dormant breaches surfacing on leak-market sites. It follows the same pattern as the hacker behind LinkedIn's 117M database claiming a further 360M Myspace user emails with passwords weeks earlier.
What makes the Last.fm figure notable is the cracking speed: Ars Technica's analysis of the full LinkedIn password dump showed how complete dumps of weakly-hashed passwords accelerate cracking of any future breach, and Last.fm's 96%-in-two-hours result is that dynamic playing out.
First-order effects
- Last.fm users whose credentials appear in the dump face immediate account-takeover risk wherever they reused those passwords, since nearly all of them are now recoverable in plaintext by anyone holding the database.
Second-order effects
- Leak brokers like LeakedSource and LeakBase gain inventory and pricing leverage from these resurfaced dumps, as seen with their handling of the later Taringa and 8tracks breaches — services built on old, weakly-hashed data become recurring saleable assets rather than one-time events.
Third-order effects
- If legacy databases keep surfacing years after the fact, the effective cost of weak password hashing extends far beyond the original incident window, pushing services toward per-user salted, slow hashes and forcing breach-response norms to assume old compromises are permanently live.
The trend: Breaches from the early-2010s era of fast, unsalted hashing are being systematically monetized years later as leak-market dumps make even decade-old password databases crackable within hours.