Data breach
Deezer
- Records
- 244,839,508
- Breach date
- 1 September 2019Estimated
- Added
- 1 December 2024
What was exposed
3 types of data · 3 more reported
- Usernames244,806,210
- Email addresses244,677,062
- Names147,852,385
- Dates of birthReported, not counted
- IP addressesReported, not counted
- GenderReported, not counted
Reported in the breach write-up; not counted in the analysed data.
About this breach
Music streaming service Deezer lost personal information on more than 244 million user accounts through a third-party provider, Which estimates the breach occurred around September 2019. The data did not surface publicly until late 2022, when it appeared on a hacker forum. Deezer says the leak came from a former service provider that kept a copy of its user data after their contract ended, not from Deezer's own systems. The company has said no passwords or payment details were included in the exposed dataset.
April 22, 2019: Date associated with the breach in external breach trackers, including Mozilla Monitor.
November 2022: Deezer says it became aware that a data leak had occurred in the systems of a former service provider, per the company's support notice. Reporting by AlternativeTo cites a November 6, 2022 forum post offering the data for sale.
January 2, 2023: The breach was added to Mozilla Monitor's database.
What Information Was Compromised?
Our analysis found the following data types in this breach: nicknames or usernames for roughly 244.8 million accounts, email addresses for about 244.7 million accounts, and names for approximately 147.9 million accounts, according to the investigation team.
Deezer's own notice confirms that first and last names, dates of birth, and email addresses were exposed. Independent reporting and breach trackers, including Mozilla Monitor, also list IP addresses, gender, geographic locations, user IDs, registration dates, and spoken languages among the compromised fields. Deezer stated in its notice that no passwords or payment details were discovered in the leak.
Not every individual is affected by every type of data listed here.
What Are the Potential Risks for Affected Individuals?
Because the exposed dataset does not include passwords or payment information, the direct financial risk is lower than in credential breaches. The more immediate risk is phishing. Criminals with a person's real name, email address, and date of birth can craft convincing emails or messages that appear legitimate, such as fake account alerts or refund offers tied to a music subscription.
The data can also support identity-related scams, unwanted marketing, and account takeover attempts in cases where attackers combine these details with passwords reused from other services. Deezer itself warns that the compromised data can be used for phishing purposes.
What Is Deezer Doing in Response?
In a notice published on its support site, Deezer said its own systems and databases were not affected and remain secure. The company said the former provider breached its contract by retaining the data after the relationship ended in 2020, despite having confirmed the data's destruction. Deezer stated it strengthened its existing security measures, is monitoring for potential fraud, has briefed customer service agents on the incident, and encourages users to change their passwords and stay alert to phishing.
What Should You Do If You Were Affected?
Change your Deezer password, especially if you have not done so since 2022.
If you reused that password on other accounts, change those passwords too.
Turn on two-factor authentication wherever it is offered, including on your email account.
Be cautious with unexpected emails claiming to come from Deezer, banks, or other services. Do not click links in suspicious messages or share personal details in reply.
Watch for signs of targeted scams, since your name, email, and date of birth may be known to attackers.
