The WaterTower Music Breach Gave Hackers Crackable Password Hashes for 66K Accounts
HEROIC analysts identified the WaterTower Music breach while monitoring underground forums and breach aggregation sites for exposed records tied to major entertainment brands. The breach dates to August 2018 and affected 66,274 user accounts belonging to the Warner Bros. in-house record label. The exposed data included email addresses and password hashes stored in a format that remains unconfirmed, which means the strength of that protection is simply not known. When you cannot verify how passwords were hashed, you have to assume the worst, and that is exactly what attackers do.
How the WaterTower Music Breach Hands Attackers a Password Cracking Head Start
Password hashes are not the same as plaintext passwords, but they are not safe either. Attackers use tools that can crack common or weak passwords from hashed values in minutes. If the hash format used by WaterTower Music was outdated or unsalted, the difficulty drops even further. Once cracked, those passwords get tested across email accounts, streaming services, and financial platforms in seperate automated campaigns. For any user who reused their WaterTower Music password, this breach is still a live threat years after it first occured.
What Was Exposed in the WaterTower Music Breach
- Email Address
- Password Hash
Why a Warner Bros. Subsidiary Breach Carries Outsized Risk
WaterTower Music is the in-house record label of Warner Bros. Entertainment. Users who registered accounts on this platform may have done so with the same email and password they use for other Warner Bros. or entertainment-related services. When a breach occurs at a corporate subsidiary, the data often connects back to broader user bases across the parent company's ecosystem. Account takeover on one service can cascade into access across related platforms. This is exactly the kind of chained risk that makes subsidiary breaches more dangerous than their record counts suggest.
How Database Breaches Work
A database breach occurs when attackers gain unauthorized access to the system that stores a platform's user records. In most cases, this involves exploiting unpatched vulnerabilities, weak credentials on administrative systems, or misconfigured cloud storage. Once inside, the attacker copies the database and either uses the data directly or sells it on criminal marketplaces. The WaterTower Music data has appeared across various underground forums since 2018, meaning it has changed hands multiple times and reached a wide audience of potential attackers.
Check If Your Data Was Exposed
HEROIC's free breach scanner searches more than 400 billion records, including the WaterTower Music breach dataset. Enter your email address to see whether your account was part of this incident. If your credentials show up, we will guide you through changing passwords and securing your accounts before attackers have a chance to act on the data.
Breach Breakdown
66,274 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds