MAZ Sound
We noticed a dataset surfacing on a well-known hacking forum in late August 2018, detailing a breach affecting MAZ Sound, a German audiophile website. What struck us was the relatively small scale of the incident, impacting just over 6,000 users, yet the persistence of such legacy data in the wild. The compromised information, primarily email addresses and MD5 password hashes, points to a common, albeit less sophisticated, attack vector. The site's subsequent closure does little to mitigate the ongoing risk posed by this exposed information.
The MAZ Sound breach, discovered on August 26, 2018, involved the exfiltration of 6,014 user records. The leaked data consists of email addresses and MD5 password hashes. This incident appears to have originated from a direct database compromise, with the compromised data subsequently published on a public hacking forum. The use of MD5, a demonstrably weak hashing algorithm, significantly increases the risk of password cracking and subsequent account takeovers, especially if users have reused credentials across other platforms. The fact that MAZ Sound is now defunct means there is no avenue for direct remediation or notification to the affected individuals through the original service provider.
While this specific incident did not garner significant mainstream media attention, the leak of MD5 hashes from defunct websites is a recurring theme in cybersecurity. Such datasets are frequently incorporated into large-scale credential stuffing attacks and are often cross-referenced with other leaked databases. Security researchers have extensively documented the vulnerabilities of MD5, highlighting its susceptibility to rainbow table attacks and brute-force methods, making even seemingly old hashes a potent threat in the hands of malicious actors.
Breach Breakdown
6,014 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds