Internet radio service 8tracks hacked, usernames, email account details, and passwords stolen; LeakBase says 18M accounts, some from 2008, affected
Context & Ripple Effects
LeakBase is becoming the recurring disclosure channel for large stolen databases: it is the same outfit that reported the Taringa breach of 28M accounts, and it operates as one of the world's largest cybercrime hubs with more than 142,000 members. The 8tracks dump fits an established pattern of old breaches surfacing years late, like the 2012 Dropbox breach that only prompted password resets long after the fact.
The stolen material — usernames, email addresses, and passwords, some dating to 2008 — matters less for 8tracks itself than for everywhere else those credentials were reused. When the Last.fm dump showed 96% of hashed passwords cracked within two hours, it demonstrated how quickly leaked password data becomes weaponizable at scale.
First-order effects
- 8tracks' roughly 18M account holders face immediate exposure of their credentials, and the service must force resets and invalidate old sessions across a user base that includes dormant accounts from 2008.
- LeakBase's 142,000+ members gain access to a fresh corpus of email-password pairs, putting the data into active criminal circulation rather than leaving it in a single buyer's hands.
Second-order effects
- Every service where 8tracks users reused passwords becomes a secondary target through credential stuffing — the same dynamic behind the Spotify credential leaks, where users reported hijacked accounts on a service that was never itself breached.
Third-order effects
- If breaches keep surfacing years after the fact through brokers like LeakBase, platforms will be pushed toward treating old password databases as permanently compromised — continuous reset policies and breach-corpus monitoring rather than one-time incident response.
The trend: Stale breach databases are resurfacing through cybercrime hubs like LeakBase years after the original intrusion, turning password reuse into a compounding liability across unrelated services.