Y-Not Radio Data Breach Exposed 2,594 Emails and Phone Numbers Online
HEROIC analysts identified the Y-Not Radio breach on February 15, 2025, after a dataset attributed to the Philadelphia-based online indie rock radio station appeared on an underground forum. The exposed records totaled 2,594 unique entries. While smaller in volume than many leaks tracked in the same period, the data types involved, full names, email addresses, phone numbers, and IP addresses, carry meaningful risk for the listeners and subscribers affected.
Why Personal Contact Data Is More Dangerous Than It Looks
This breach contains no passwords, but that does not make it harmless. A record that pairs a full name, email address, and phone number gives an attacker everything needed to impersonate a trusted contact, craft a convincing phishing message, or launch a SIM-swapping attack to hijack the victim's phone number. IP addresses add another dimension: they can reveal approximate geographic location and, when cross-referenced with other leaked datasets, help attackers build detailed profiles of individual targets. For a niche community like an indie radio audience, where users may share personal contact details expecting a safe, low-profile environment, the exposure carries an outsized trust violation.
What Was Exposed in the Y-Not Radio Breach
- Email addresses: Primary contact point and username for most online accounts
- Phone numbers: Enables SMS phishing, robocalls, and SIM-swap attacks
- First and last names: Allows personalized, targeted social engineering
- IP addresses: Reveals approximate location and browsing context at time of data capture
Why This Matters: How Contact Data Fuels Identity Theft
Attackers who acquire this type of dataset rarely use it in isolation. The combination of name, email, and phone number is frequently merged with other breached datasets to build richer profiles, a technique known as data enrichment. Those enriched profiles are then sold to fraud operations, used in targeted phishing campaigns, or deployed in account recovery attacks where the attacker poses as the victim to regain access to accounts they do not own. The IP addresses in this breach also enable geographic targeting, making social engineering calls and messages appear locally relevant and more convincing.
How Database Breaches Happen at Small Media Platforms
Independent radio stations and small media platforms often manage listener and subscriber data through third-party plugins, mailing list software, or lightly maintained content management systems. Security updates may lag, and dedicated IT security staff are rarely part of the budget. Attackers specifically target smaller platforms because the defenses are lower and the data, while smaller in volume, is still valuable for profiling and social engineering. A single outdated plugin or an unpatched login portal is often all it takes for a database to be extracted and circulated online.
Check If Your Information Was Exposed in the Y-Not Radio Breach
HEROIC's free breach scanner searches across more than 400 billion compromised records to tell you exactly what information of yours has been exposed in known data breaches. If you ever registered with Y-Not Radio or used the same email address across multiple services, a quick scan can confirm whether your name, email, or phone number is already in circulation. Check your exposure now at HEROIC before someone else acts on your data first.
Breach Breakdown
2,594 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds