Disclaimer: as technology changes, advisories may become out of date or may no longer be relevant, please refer to the "Date" section of the header to be sure the advisory is recent as pertains to your situation.
Keywords: MySpace, compromise, passwords, email addresses, unsalted
DBSA ID: 2016-05271
Regarding: MySpace Compromise
Date: 2016 05 27
Last Modified: 20160527162739 by Kradorex Xeron
Who should take note: All MySpace Users
Rationale: Users need to ensure their information is secured.
Rationale: Usernames, insecurely hashed passwords, email addresses among other information has reportedly been compromised
Spread of Issue: SINGLE-PLATFORM HIGH
Rationale: 427 Million records are reported to have been compromised
MySpace is a social networking platform website created for users to communicate, recent iterations of the website have been targeted toward the independent music scene. On 27 May 2016 it has been reported that the backend database of the site had been compromised and analyzed by the attackers who indicate 427 million records are in their posession. Records contain usernames, hashed passwords that are not salted (making it easy to use a rainbow table attack) and email addresses.
Digibase has not directly observed the compromised records, so this is unconfirmed at this point in time, but users should deploy standard methodologies.
Users should change their Myspace passwords on a rolling basis to temporary passwords, once immediately and then again at 1 weeks. After 2 weeks users may reset to a more longterm password. Users should also ensure that their password is not shared among other sites, to which those passwords will also need to be reset.
Users should also be highly suspicious of any contacts via email and use non-email methods to verify legitimacy of such email. Password resets should only be performed through known good links.