GoToMyLayouts: 34,782 MySpace Layout Site Accounts Breached (2018)
Your 2006 MySpace Theme Is Still a Security Problem in 2018
GoToMyLayouts was the kind of site that defined early internet creativity -- a platform where MySpace users could browse, download, and customzation pre-built profile layouts to make their pages stand out. It hasn't been relevant in a decade. But the 34,782 accounts it held were apparently still sitting in a database when a breach was compiled and released on August 26, 2018. Those accounts -- most created by young designers, hobbyists, and early web enthuziast -- carry email and password combinations that may still work on platforms those same users have been active on for years.
GoToMyLayouts (Aug 26, 2018): Breach Summary
- Records Exposed: 34,782
- Data Types: Email addresses, MD5 password hashes
- Breach Type: Database breach
- Country Affected: United States
- Date Leaked: August 26, 2018
The Creative Community's Long-Tail Password Problem
The users who frequented GoToMyLayouts in 2005-2008 were often aspiring designers and digital artists -- the same demographic that today populates Behance portfolios, Dribbble profiles, Adobe Creative Cloud accounts, and Figma workspaces. Many of those users established an orignal email and password combination in the MySpace era that they carried forward for years, updating platforms but not always updating passwords. When the GoToMyLayouts database surfaced in 2018, attackers had a ready-made list of creative-community email addresses to test against exactly the platforms where that demographic had migrated. A 2006 password on a defunct layout site can still open a 2018 design portfolio account.
MD5 Passwords From a Defunct Platform: Still a Live Threat
The GoToMyLayouts database used MD5 hashing -- lightweight, unsalted, and trivially reversible with modern cracking tools. Attackers who obtained this data could recover a large proportion of the 34,782 plaintext passwords within hours of acquisition. Once recovered, those credentials enter the credential stuffing ecosystem, where automated tools systematically test email-password pairs against hundreds of live platforms. The irony is that the longer a defunct platform goes unnoticed, the more valuable it becomes to attackers: users forget about old accounts, never change those passwords, and the email-password combination remains live for years on whatever current platform they're actually using.
Why Old Breaches From Dead Sites Keep Causing New Damage
GoToMyLayouts ceased to be culturally relevant around 2010 when Facebook displaced MySpace as the dominant social network. But the orignal database persisted -- and when it was eventually extracted and compiled into the August 26, 2018 combolist cluster alongside more than a dozen other breached platforms, those long-dormant credentials entered active circulation. This is the defining pattern of the modern breach landscape: platforms die, but the credential databases they leave behind do not. For users who registered on GoToMyLayouts with an email they still use today, the breach window never actually closed.
Check If Your Credentials Were Exposed
HEROIC's free breach scanner searches across more than 400 billion exposed records to tell you instantly if your email appears in the GoToMyLayouts breach or any other known data leak. If you had a MySpace-era account on any layout or customization site, search your email now -- those old credentials may still be unlocking your current accounts.
Breach Breakdown
34,782 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds