Tuned Global
We're seeing an uptick in older breaches resurfacing, likely due to threat actors re-evaluating previously discarded datasets for newly exploitable information. What struck us about the Tuned Global breach wasn't the volume of records, but the age of the data combined with the sensitive nature of the information, specifically the presence of plaintext passwords. The fact that this data, dating back to March 2016, is still circulating and potentially being used in credential stuffing attacks highlights a persistent risk for both users and enterprises. This re-emergence underscores the need for continuous monitoring of data leak repositories and proactive password resets, even for seemingly outdated breaches.
The Music Streaming Service Breach: 981k Records with Plaintext Passwords
In January 2021, a database dump from Tuned Global, a B2B music streaming service, was posted on a well-known hacking forum. The breach, stemming from March 2016, exposed nearly a million user records. The primary concern lies in the fact that passwords were stored in plaintext, a practice considered highly insecure even at the time of the breach. This significantly increases the risk of successful account takeovers across other platforms where users may have reused the same credentials.
The breach initially caught our attention due to the age of the data and the unusual storage of passwords in plaintext. While large breaches are common, the combination of these factors suggests a lack of basic security hygiene at the time of the incident. This is particularly concerning given that Tuned Global provides services to other businesses, potentially amplifying the impact of the breach through supply chain vulnerabilities.
This breach matters to enterprises now because it serves as a stark reminder of the long-term consequences of poor security practices. Even if the immediate fallout from the 2016 breach has subsided, the leaked credentials remain a threat. Enterprises should proactively monitor for compromised credentials related to their domain and encourage employees to update their passwords, especially if they used the same credentials on other platforms. This incident ties into the broader threat theme of credential reuse and the enduring value of older data breaches to attackers.
- Total records exposed: 981,471
- Types of data included: Email Address, Plaintext Password, First Name, Last Name
- Sensitive content types: PII (Personally Identifiable Information)
- Source structure: Database dump
- Leak location(s): Popular hacking forum
- Date of first appearance: January 2021 (initial breach in March 2016)
External Context & Supporting Evidence
While there is limited mainstream media coverage of the specific Tuned Global breach, the incident aligns with broader trends in data security and credential stuffing attacks. Security researchers have consistently warned about the dangers of plaintext password storage and the importance of using strong, unique passwords across different platforms. The re-emergence of this data highlights the persistent risk posed by older breaches and the need for continuous monitoring and remediation efforts.
The practice of storing passwords in plaintext is a well-documented security vulnerability. Multiple resources and articles exist online detailing the risks associated with it. For example, OWASP (Open Web Application Security Project) provides extensive guidance on secure password storage practices, emphasizing the use of salting and hashing algorithms to protect user credentials.
Breach Breakdown
981,471 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds