Credentials tied to roughly 360 million Myspace accounts are being offered for sale in an online criminal market, one of the largest collections of stolen passwords ever disclosed and a warning that abandoned accounts can remain dangerous years after users stop visiting a service.
Myspace said the data include email addresses, usernames and passwords for accounts created before June 11, 2013, when the social network relaunched with stronger security. The company has invalidated known affected passwords, is notifying users and is working with law enforcement. Time Inc., Myspace’s parent, confirmed the breach Tuesday and said other Time systems, subscribers and properties were not affected.
Old accounts produce a current security crisis
The precise date of the intrusion is unclear. Myspace described the records as originating from its old platform, which means the theft may have occurred years before the database surfaced. The seller, using the name “Peace,” has recently been linked to large credential collections from LinkedIn and Tumblr.
Security researchers examining the Myspace archive say it contains about 360 million accounts and 427 million passwords because some records include a secondary password. Wired’s analysis of the sale reported that the data were advertised for six bitcoin, worth several thousand dollars, on the Real Deal marketplace.
The episode demonstrates a mismatch between how people think about dormant accounts and how attackers value them. A user may regard a long-unused social profile as irrelevant. But its email address, password and username can become a key for testing other services. If the password was reused, a breach at Myspace can unlock a current bank, shopping, email or workplace account.
Variety reported that Time acquired Myspace in February through its purchase of Viant and learned of the offered data shortly before the Memorial Day weekend. The ownership change means the company now inherits security liabilities created under earlier operators.
Weak hashing makes passwords easier to recover
Passwords should not be stored as readable text. Services typically transform them with a one-way cryptographic hash, then compare hashes when users log in. But the protection depends on the algorithm and on whether each password receives a unique random “salt” before hashing.
The Myspace passwords were reportedly stored with the SHA-1 algorithm without salting, and only the first 10 characters were considered after converting letters to lowercase. That design substantially reduces the number of possible combinations and allows attackers to test enormous dictionaries of likely passwords quickly. A long mixed-case password loses much of its advantage when a system discards characters and capitalization.
ESET’s WeLiveSecurity account said Myspace’s technical team confirmed the offered information was genuine and that the company now uses stronger, double-salted hashes. Improved current storage cannot retroactively protect the older database once attackers possess it.
The breach therefore carries two dates: the unknown moment when records were copied and the present moment when they became exploitable at scale. Disclosure is not the beginning of the incident for Myspace, but it is the beginning of risk for many people who did not know their credentials had escaped.
A cluster of breaches reveals a larger market
The Myspace records appeared amid disclosures involving other once-dominant networks. LinkedIn reset passwords after data from a 2012 breach expanded from the 6.5 million accounts initially known to roughly 165 million. Tumblr disclosed that a 2013 incident exposed email addresses and hashed passwords; investigators now estimate about 65 million accounts were involved.
Wired’s report on the Tumblr sale noted that its passwords were salted before hashing, making them harder to crack than the Myspace archive, though still valuable for phishing and correlation. The simultaneous appearance of several old databases suggests that stolen credentials can circulate privately for years before reaching a public market.
This secondary market changes the economics of a breach. Attackers do not need to use every account themselves. They can sell collections to spammers, identity thieves and operators who automate “credential stuffing”—trying the same email-password pair across popular websites. The scale of 360 million records makes even a low success rate profitable.
A June 1 report by PYMNTS emphasized that the compromised information came from the pre-2013 system and that Myspace was monitoring for suspicious activity. Monitoring the breached service alone cannot detect attacks on unrelated sites, however, which is why password reuse is the central danger.
Users must respond beyond Myspace
Anyone who held a Myspace account before June 2013 should change the password anywhere it was reused, beginning with the associated email account. Email access is especially sensitive because it can be used to reset passwords for other services. Users should create a unique password for each account and enable two-factor authentication where available.
Password managers can generate and store long, random credentials, reducing both reuse and the burden of remembering them. Services, meanwhile, should use deliberately slow password-hashing functions with unique salts, monitor for automated login attempts and support a second authentication factor.
The Hacker News’s technical account reported that the database includes hundreds of millions of unsalted SHA-1 hashes and urged immediate changes on every site where an old Myspace password was repeated. Myspace’s forced reset protects only the Myspace login.
The company said no financial information was included. That limitation reduces direct fraud risk but does not make the records harmless. Email addresses can support targeted phishing, usernames connect identities across sites and passwords reveal personal habits that attackers can adapt.
Security obligations outlast a product’s popularity
Myspace was the leading American social network before Facebook surpassed it. Its decline may have reduced how often users visit, but it did not erase the database accumulated at its peak. The incident shows that companies retain a security obligation for as long as they retain personal information, regardless of whether a service remains culturally prominent.
It also raises questions about acquisitions. Buyers obtain not only brands and software but historical user records, security architecture and undiscovered compromises. Due diligence must account for systems that have been retired, because attackers may possess copies even when the company no longer operates the original platform.
A contemporaneous account of Myspace’s response said all known affected passwords had been invalidated and users would be notified. Those are necessary steps, but the broadest harm now lies outside Myspace’s control.
The breach’s extraordinary size is partly an artifact of Myspace’s former success. Hundreds of millions of people entrusted the network with credentials, then moved on. The data did not. In an online economy built on durable accounts and reusable identifiers, a forgotten password can remain valuable to an attacker long after it has been forgotten by its owner.