Pwned: 65 million Tumblr accounts, 40 million from Fling, 360 million from MySpace (2024)

Pwned: 65 million Tumblr accounts, 40 million from Fling, 360 million from MySpace (1)

byDarlene Storm

news analysis

May 30, 20163 mins

CybercrimeData and Information SecurityPrivacy

That "set" of accounts compromised in the Tumblr hack was actually 65 million. Have I Been Pwned added another 40 million from the 'dating' hookup site Fling. The MySpace hack had more than 360 million email addresses in it.

After signing up for Have I Been Pwned? when Troy Hunt started the site in 2013, I had received no notifications about any account being compromised in a data breach. But then whammo! I get two notifications for two separate breaches in a relatively short time. The one today was about Tumblr, an account I barely remember even signing up for.

Over 65 million Tumblr accounts compromised

Tumblr claimed “a third party had obtained access to a set of Tumblr user email addresses with salted and hashed passwords from early 2013.” The reality, according to the HIBP notification, is that 65,469,298 people were pwned in the Tumblr data breach from February 2013; the compromised data included email addresses and passwords.

In other words, dumped data from another old hack came out of nowhere and jumped to number three inHIBP’stop 10 breaches.

A hacker going by “peace_of_mind” was selling the Tumblr data on the darknet marketplace The Real Deal.

Peace told Motherboard that Tumblr had used SHA1 to hash the passwords and also used salt, making them hard to crack. The data is “essentially just a list of emails” and “he was only able to sell it for $150.”

Over 40 million Fling accounts compromised

Before adding the Tumblr accounts to HIBP, security researcher Troy Hunt reported that he had just added 40,767,652 compromised records from Fling, which is not safe for workor around children if you click on it. The Fling breach dated back to 2011.

“Peace” is also selling the compromised account data from Fling, LinkedIn, Tumblr and MySpace.

Data from mega breaches no longer ‘dormant’

The LinkedIn hack of 2012 supposedly exposed 6.2 million password hashes, but that ended up missing the mark by a tremendous amount since a hacker was selling 167 million LinkedIn user records. 117 million had passwords, which were stored in SHA1 with no salting.

Then there’s more than 65 million accounts compromised from Tumblr and over 40 million from Fling. “This data has been lying dormant (or at least out of public sight) for long periods of time,” Hunt wrote.

Although the total records added to HIBP in the last six days is 269 million, Hunt said all of those latest hacks will “pale in comparison” once he gets hold of and adds the compromised MySpace records.

MySpace hack

The MySpace hack contained over 360 million email addresses in it.

LeakedSource reported the “data set contains 360,213,024 records. Each record may contain an email address, a username, one password and in some cases a second password. Of the 360 million, 111,341,258 accounts had a username attached to it and 68,493,651 had a secondary password.”

The data, which had been provided by “Tessa88,” included 427,484,128 total passwords that were stored in SHA1 with no salting. Sadly, “very few passwords were over 10 characters in length (in the thousands) and nearly none contained an upper case character.” MySpace had chosen not to respond when contacted, so LeakedSource has included a list of top passwords as well as the top email domains.

LeakedSource, which has accumulated over 1.6 billion records, has search capabilities. If you find your personal information in the leaked databases, you can contact LeakedSource and ask for it to be “removed free of charge.”

This “trend” of data being sold from really old hacks has Hunt “really curious.” He wrote, “Even if these events don’t all correlate to the same source and we’re merely looking at coincidental timing of releases, how many more are there in the ‘mega’ category that are simply sitting there in the clutches of various unknown parties?”

Related content

  • featureWindows 11 Insider Previews: What’s in the latest build? Get the latest info on new preview builds of Windows 11 as they roll out to Windows Insiders. Now updated for Build 22635.3720 for the Beta Channel and Build 26120.770 for the Dev Channel, both released on June 7, 2024.ByPreston GrallaJun 07, 2024264 minsSmall and Medium BusinessMicrosoftWindows 11
  • newsDuckDuckGo launches anonymous AI chatbot The privacy-conscience search engine said it will not use information users input for training LLMs or in any other way reveal who queried the chatbot.ByLucas MearianJun 07, 20243 minsChatbotsData PrivacyWeb Search
  • newsUS chip export control rules circumvented by AI cloud services, says report Chinese companies are exploiting a loophole in export control rules that draft legislation introduced last year sought to close.ByJohn LeydenJun 07, 20244 minsGovernmentGenerative AIGPUs
  • newsHow many jobs are available in technology in the US? Tech unemployment was down in May and job postings were higher than they've been for more than a year.ByLucas MearianJun 07, 2024164 minsRemote WorkSalariesFinancial Services Industry

SUBSCRIBE TO OUR NEWSLETTER

From our editors straight to your inbox

Get started by entering your email address below.

Pwned: 65 million Tumblr accounts, 40 million from Fling, 360 million from MySpace (2024)

FAQs

Has Tumblr been hacked? ›

Tumblr was breached in 2013, yet the company only discovered it and notified its users in May 2016. Apparently, the passwords were hashed and salted, according to an analysis by Tray Hunt, but Tumblr did not state the algorithm used in the process. That is why the selling price was fairly low.

Have I been pwned is safe? ›

The site is simply intended to be a free service for people to assess risk in relation to their account being caught up in a breach. As with any website, if you're concerned about the intent or security, don't use it.

Did Myspace get hacked? ›

MySpace, once the largest social networking site, experienced a massive data breach that came to light in 2016. The breach itself reportedly occurred years earlier, around 2013, but its full extent only became widely known when stolen data was found being offered for sale on dark web marketplaces.

Have I been pwned owner? ›

Troy Hunt, the creator of Have I Been Pwned? In late 2013, web security expert Troy Hunt was analyzing data breaches for trends and patterns. He realized breaches could greatly impact users who might not even be aware their data was compromised, and as a result, began developing HIBP.

Can Tumblr track you? ›

Location Information: In some cases we collect and store information about where you are located, such as by converting your IP Address into a rough geolocation. We may also ask you to provide information about your location, for example to use your geolocation information from your mobile device to geotag a post.

Is Tumblr still blocking NSFW? ›

Reversing a 2018 ban, the company said that nudity and “mature subject matter” would be allowed. But “visual depictions of sexually explicit acts” remain off limits. Tumblr, the once-popular social media platform, is again allowing nudity, four years after announcing a ban on explicit content.

What does a pwned email address mean? ›

', 'pwned' means that someone has taken control of your email address, or a user profile that has been created with it.

Is downloading leaked passwords illegal? ›

Passwords are not protected by copyright. If Google were to induce someone to break into a computer system to get passwords, that would be legally actionable, however there is no law penalizing innocent receipt of illegally-obtained passwords (insofar as they are not protected by copyright).

How do you know if your personal data has been hacked? ›

Watch your accounts, check your credit reports

Read your credit card statements and watch for suspicious transactions. Also, sign up for your free annual credit report to check your credit reports from each of the three credit reporting bureaus.

Does your old Myspace account still exist? ›

Your Myspace profile from the Classic site is still here. Here is a collection of articles about logging in, signing up, and activating your profile.

Do people actually still use Myspace? ›

Myspace is still active today, but it's a shell of its former self. No new articles have been published since early 2022 and existing songs or media cannot be played. The site's privacy policy was last revised on 9 January 2023, and it's has been placed on a strange, read-only mode since then.

Is my identity on the dark web? ›

How to Find Out if Your Information is on the Dark Web. All you need is a service that automatically checks the Dark Web for you. Bitdefender Digital Identity Protection scans the Dark Web to find if your personal information was exposed. It also helps you take action to protect your data.

Has my phone number been in a data breach? ›

How To Check If My Phone Number Is Leaked. Go to ID Protection Data Leak Checker and find out if your phone number appeared in any data leaks.

Is it safe to use Tumblr? ›

Rating: The dangers of Tumblr are essentially the same as every other major social media platform. It's not hard to find sexual content (more on that in a moment), violence, and cyberbullying. Additionally, Tumblr has gotten a bad rap for being the place to find self-harm and suicidal content in a glorified context.

Why did everyone stop using Tumblr? ›

While the adult content ban increased ad revenue in the short term, it ultimately finalized Tumblr's decline in user engagement and influence. The platform lost its niche appeal without successfully attracting a new audience and struggled to find a new identity.

Is anyone still using Tumblr? ›

Tumblr has a loyal and engaged community: Despite the decline in user base and traffic, Tumblr still has a loyal and engaged community of users, who spend more time on the platform than on other social media networks.

Can you see who stalks your Tumblr? ›

Because Tumblr doesn't natively offer visitor tracking and statistics, however, you have to rely on an external tool, such as Google Analytics.

Top Articles
Latest Posts
Article information

Author: Jeremiah Abshire

Last Updated:

Views: 5573

Rating: 4.3 / 5 (54 voted)

Reviews: 93% of readers found this page helpful

Author information

Name: Jeremiah Abshire

Birthday: 1993-09-14

Address: Apt. 425 92748 Jannie Centers, Port Nikitaville, VT 82110

Phone: +8096210939894

Job: Lead Healthcare Manager

Hobby: Watching movies, Watching movies, Knapping, LARPing, Coffee roasting, Lacemaking, Gaming

Introduction: My name is Jeremiah Abshire, I am a outstanding, kind, clever, hilarious, curious, hilarious, outstanding person who loves writing and wants to share my knowledge and understanding with you.