
Loading

Loading
We use strictly necessary cookies to run this site, and analytics cookies to understand how it's used. See our Privacy Policy for details.
8tracks.com
What happened
In June 2017, the online playlists service known as 8Tracks suffered a data breach which impacted 18 million accounts. In their disclosure, 8Tracks advised that "the vector for the attack was an employee’s GitHub account, which was not secured using two-factor authentication". Salted SHA-1 password hashes for users who didn't sign up with either Google or Facebook authentication were also included. The data was provided to HIBP by whitehat security researcher and data analyst Adam Davies and contained almost 8 million unique email addresses. The complete set of 18M records was later provided by [email protected] and updated in HIBP accordingly.
Data exposed
Frequently asked questions
The 8tracks data breach occurred on June 27, 2017. It was added to Have I Been Pwned's breach catalog on February 16, 2018.
17,979,961 accounts were affected by the 8tracks data breach, according to Have I Been Pwned's records.
The 8tracks breach exposed the following data types: Email addresses, Passwords.
Yes. Have I Been Pwned has verified the 8tracks breach, meaning there's confirmed evidence the exposed data is genuine and tied to real accounts.
Use KazaSec's free Email Breach Checker (/tools/breach-check) to check whether a specific email address has surfaced in the 8tracks breach, or any other known breach — the tool never stores what you search.
Our free Email Breach Checker tells you whether a specific email address has surfaced in this breach — or any other known breach — without ever storing what you search.
Check your email →Talk to us about this
We help organizations find and fix the gaps that lead to a breach, before they do.