Back to Blog

LeakedSource Analysis of Last.fm Hack

LeakedSource Team
|
September 1st, 2016

Table of Contents

  • About Us
  • Summary
  • Passwords
  • Emails
  • Site Growth
  • About us

    LeakedSource has exposed every single mega breach of 2016 including LinkedIn, MySpace, and VK.com but because we are the most effective breach notification service in the world, we're back with more.

    We have already helped multiple companies, many of them worth billions of dollars, to secure their users with our API which provides cracked plaintext passwords from all 2 billion leaked records. Businesses are then easily able to compare leaked passwords against their own users and if a match is found, they forcibly change the passwords for affected users. If you're interested in using our services, contact us about an API key.

    Any journalists that want to get notified about breaches, DM us on Twitter with your email address

    One final note about the state of affairs on the internet: We have so many databases waiting to be added that if we were to add one per day it would still take multiple years to finish them all. We are also currently processing multiple more mega breaches so stay tuned to our Twitter.

    Summary

    Music service Last.fm was hacked on March 22nd, 2012 for a total of 43,570,999 users. This data set was provided to us by [email protected] and Last.fm already knows about the breach but the data is just becoming public now like all the others.

    Each record contains a username, email address, password, join date, and some other internal data. We verified the legitimacy of this data set with Softpedia reporter Catalin C who was in the breach himself along with his colleagues.

    Anyone may use any information on this page for free provided LeakedSource is given credit and a direct link back.

    You may search for yourself any of the leaked databases by visiting our homepage. If your personal information appears in our copy of this database, or in any other leaked database that we possess, you may remove yourself for free.

    Passwords

    Passwords were stored using unsalted MD5 hashing. This algorithm is so insecure it took us two hours to crack and convert over 96% of them to visible passwords, a sizeable increase from prior mega breaches made possible because we have significantly invested in our password cracking capabilities for the benefit of our users. Here are the top 50:
    Rank Password Frequency
    1 123456 255,319
    2 password 92,652
    3 lastfm 66,857
    4 123456789 63,984
    5 qwerty 46,201
    6 abc123 36,367
    7 abcdefg 34,050
    8 12345 33,785
    9 1234 30,938
    10 music 27,975
    11 12345678 25,876
    12 111111 25,313
    13 abcdefg123 21,555
    14 aaaaaa 19,098
    15 123123 18,147
    16 123 17,225
    17 liverpool 17,191
    18 1234567 17,168
    19 000000 16,941
    20 monkey 16,787
    21 football 16,177
    22 1234567890 14,972
    23 666666 14,164
    24 password1 14,016
    25 last.fm 13,741
    26 xbox360 13,467
    27 baseball 12,645
    28 iloveyou 12,160
    29 dragon 12,134
    30 shadow 11,893
    31 123321 11,281
    32 abcd 11,141
    33 foxpass 10,719
    34 fuckyou 10,685
    35 cheese 10,669
    36 musica 10,651
    37 soccer 10,288
    38 654321 9,969
    39 sunshine 9,925
    40 arsenal 9,894
    41 metallica 9,891
    42 superman 9,842
    43 charlie 9,839
    44 daniel 9,775
    45 abcdef 9,376
    46 letmein 9,306
    47 killer 9,174
    48 abcde 9,124
    49 blink182 9,099
    50 michael 8,997

    Emails

    Most popular email domains used by Last.fm users
    Rank Email provider Frequency
    1 @hotmail.com 9,374,285
    2 @gmail.com 8,314,471
    3 @yahoo.com 6,509,598
    4 @aol.com 1,118,612
    5 @hotmail.co.uk 1,020,710
    6 @mail.ru 883,477
    7 @live.com 590,762
    8 @web.de 503,368
    9 @msn.com 414,873
    10 @gmx.de 408,387
    11 @wp.pl 303,181
    12 @yahoo.co.uk 293,510
    13 @yandex.ru 292,537
    14 @comcast.net 262,715
    15 @googlemail.com 260,146
    16 @hotmail.fr 241,080
    17 @o2.pl 215,680
    18 @live.co.uk 209,396
    19 @aim.com 209,076
    20 @yahoo.com.br 196,509
    21 @ymail.com 191,356
    22 @qq.com 190,087
    23 @yahoo.de 148,170
    24 @rambler.ru 147,313
    25 @163.com 146,898
    26 @sbcglobal.net 142,929
    27 @hotmail.it 141,774
    28 @gmx.net 138,736
    29 @yahoo.fr 126,680
    30 @hotmail.de 121,234
    31 @yahoo.es 115,416
    32 @btinternet.com 112,637
    33 @yahoo.co.jp 108,474
    34 @rocketmail.com 94,318
    35 @interia.pl 90,088
    36 @libero.it 83,068
    37 @t-online.de 80,845
    38 @op.pl 79,629
    39 @mac.com 78,211
    40 @verizon.net 75,541
    41 @att.net 73,249
    42 @bk.ru 72,818
    43 @seznam.cz 70,697
    44 @126.com 68,256
    45 @me.com 65,094
    46 @freenet.de 62,357
    47 @list.ru 62,246
    48 @inbox.ru 61,428
    49 @yahoo.it 59,290
    50 @hotmail.es 58,863

    Site Growth

    When registration dates are available, sometimes we like to see how long it took the website to get millions of users.
    Year New users
    2002 3,455
    2003 33,234
    2004 232,584
    2005 883,160
    2006 2,121,072
    2007 3,334,039
    2008 5,567,903
    2009 10,618,617
    2010 10,189,640
    2011 8,940,538
    2012 1,646,757

    Check Your Breach Exposure

    Find out if your email address has been compromised in any known data breaches.

    Scan Your Email Now