MySpace

High

About 359 million email addresses sat in the MySpace credential file stolen around 2008 and sold in 2016 — usernames plus weak password hashes, not a modern scrape. Check whether your address is in that file, then treat any reused password as the first job.

359.4M
Records exposed
2008
Year
3
Data types
Free
To check
Check if you were affected — free

Quick answer — was MySpace breached?

Yes — this page is the ~2008 MySpace password-database theft that was offered for sale in May 2016, about 359 million unique emails with usernames and SHA-1 password hashes. It is not a later Facebook- or Twitter-style scrape. A match means your address appeared in that credential file. Check if you were affected.

What happened in the MySpace data breach?

This catalog row is the old MySpace credential file — emails, usernames, and weakly stored passwords — not a later social-media scrape. The theft itself was never given a precise company date. Independent analysis of the circulating file puts it around mid-2008 to early 2009. In May 2016 a seller listed almost 360 million accounts on a dark-web market. This lookup lists about 359.4 million unique email addresses.

The passwords were stored as unsalted SHA-1 hashes of only the first ten characters, after converting the password to lowercase. That is not modern hashing. Identical short passwords produced identical hashes, and case and anything past character ten did not count. People who had left MySpace still reused those strings on email and shopping sites. Deleting the MySpace profile later did not pull the 2016 sale back.

Contemporaneous counts sometimes said about 427 million password hashes because some rows carried a second password. The unique-email count in this catalog is about 359.4 million. MySpace said accounts created before a 11 June 2013 platform change were the ones at risk, and it invalidated those old passwords. That closes MySpace. It does not close any other site that still shared the string. Learn more about what a data breach means for you.

Why was the MySpace breach so dangerous?

The passwords were stored as unsalted SHA-1 hashes of only the first ten characters, after converting the password to lowercase. That is not modern hashing. Identical short passwords produced identical hashes, and case and anything past character ten did not count. People who had left MySpace still reused those strings on email and shopping sites. Deleting the MySpace profile later did not pull the 2016 sale back.

Yes, if that mid-2000s MySpace password was ever reused and has not been changed. The file is old, widely copied, and still useful for credential stuffing. A unique password plus an authenticator-app second factor is what ages this incident out of your life. Closing or ignoring MySpace does not retire the same string on email.check whether your email was exposed in this breach.

What data was stolen in the MySpace breach?

Email addresses Passwords Usernames

Email addresses — used for phishing attacks and credential stuffing against your other accounts

Passwords — can be used to access your accounts directly or cracked to reveal your actual password

Usernames — used to build profiles and target you with personalised scams

Timeline of the MySpace breach

Mid-2008 to early 2009

Best public estimate for when the MySpace credential file was taken, based on independent analysis of email-provider mix and account-creation dates in the later sale

2008–2016

The file is held or traded privately; MySpace users are not given a public notice in that window

May 2016

A seller lists almost 360 million MySpace accounts on a dark-web market — emails, usernames, and SHA-1 password hashes

31 May 2016

MySpace confirms stolen usernames and passwords for accounts created before 11 June 2013 and invalidates those old credentials

31 May 2016

Independent write-up of the file: unsalted SHA-1 of the first ten lowercase password characters; about 359.4 million unique emails

2016–2026

Copies remain in credential-stuffing lists; leftover reused passwords from the file still unlock other sites

Is the MySpace breach still dangerous in 2026?

Yes, if that mid-2000s MySpace password was ever reused and has not been changed. The file is old, widely copied, and still useful for credential stuffing. A unique password plus an authenticator-app second factor is what ages this incident out of your life. Closing or ignoring MySpace does not retire the same string on email.

Email addresses from a 2008-era social network do not expire as phishing targets. Unique passwords and two-factor authentication are the work. Learn how long stolen data stays dangerous.

How is this different from later social scrapes?

A password-database theft and a public-profile scrape are different failures. This row is the first kind: attackers copied MySpace stored logins. The circulating file had an internal ID, an email, a username, and one or two password hashes. It did not include the later mix of phone numbers, bios, and follower counts that appear in 2020s social scrapes.

The hashes themselves were unusually weak even for 2008. Researchers who opened the 2016 sale described SHA-1 of the first ten characters, forced to lowercase, with no salt. That is why leftover reuse still matters in 2026: a cracked short password is a working login anywhere it was repeated.

Other 2016 sales — LinkedIn from 2012, Tumblr from 2013 — were listed in the same season. They are separate catalog rows. Do not fold them into this match.

  • This row — ~2008 MySpace credentials sold in 2016. Emails, usernames, weak password hashes.
  • Later social scrapes — phones and public profile fields. Different rows, different playbook.
  • A match here is the password playbook. Fix reuse. Do not hunt for a live MySpace session as the whole job.

What does an EmailLeaked MySpace match mean?

If your address is in the 2008-era credential file, EmailLeaked shows a named MySpace match the same way it shows any other named incident. The row is a lookup against industry-standard breach data sources. We do not claim an exclusive copy of the 2016 sale, and we do not crawl hidden markets live.

A match is not proof someone opened a MySpace page this week. It is evidence that the address — and typically a weak password hash from that era — appeared in a file that has been public since 2016. A miss is a snapshot of the records we can search today. We do not keep the address you type into the checker. Hosting logs and a privacy-oriented analytics beacon can still record that the page was visited.

If you want the response order in one place, use what to do after a data breach. If you want to test a reused password without sending the full password, use the password leak checker. For a second public index, see free data breach checkers.

What to do if your email was in the MySpace breach

1

Confirm the match and what was listed

Run the email check if you need the named incidents in one list. This MySpace row lists emails, usernames, and passwords. That is the password playbook, not a scrape playbook.

Check this email — free
2

Treat any reused password as public

Change the password on every site that shared the old MySpace string — starting with email. Then check whether that password appears in known leaks without sending the password itself.

3

Turn on two-factor authentication

Start with email. An authenticator app is stronger than a text-message code. A stuffing bot that has the 2008-era password still fails if the second factor is not sitting on a leaked phone number.

4

Follow the after-breach playbook

Use the first-hour and 24-hour lists, then the password playbook. Walk the account security checklist so recovery email, sessions, and leftover logins get a pass.

Open the after-breach playbook
5

Compare how public checkers differ

A second lookup does not change the 2016 sale. It can show you how different public indexes present the same named incident.

Read the checker comparison
6

Close leftover MySpace if you still have a login

Deletion does not unsay the 2016 sale. It stops an old social login from sitting around. If the profile is already gone, still retire any password you reused there.

Browse delete-account guides

Frequently asked about the MySpace breach

What happened in the MySpace data breach this page covers?
A MySpace user-credential file from around 2008 was offered for sale in May 2016. This catalog row is about 359.4 million unique email addresses with usernames and SHA-1 password hashes. MySpace said accounts created before 11 June 2013 were the ones at risk.
How were MySpace passwords stored?
Researchers who opened the 2016 sale described SHA-1 hashes of the first ten characters of the password, converted to lowercase, with no salt. That made common short passwords cheap to recover. A cracked hash is a working password anywhere it was reused.
Why do some articles say 427 million passwords?
Some rows carried a second password, so contemporaneous counts of hashes ran higher than the unique-email count. This lookup follows the unique-email figure: about 359.4 million.
I deleted my MySpace account years ago — am I still at risk?
Yes, if you reused that password anywhere and have not changed it. Deletion removes the live profile. It does not unsay the 2016 sale. Treat leftover reuse, then use a unique password and two-factor authentication.
How does EmailLeaked show a MySpace match?
As a named row in the email checker, using industry-standard breach data sources. This explainer is the plain-English layer: ~2008 credentials sold in 2016, typically emails and passwords, not a later scrape. We do not claim exclusive ownership of the file.
Is the MySpace breach still dangerous in 2026?
Yes, if the password has not been changed on every site that shared it. The file is widely copied. Unique passwords and two-factor authentication are what age it out of your life.

How this breach page is reviewed

Breach pages are built from structured breach records and reviewed for practical risk guidance by EmailLeaked. Risk labels reflect exposed data types and are intended to help readers prioritise action.

Was your email in this breach?

Check if your email appeared in the MySpace breach and 1033+ other known breaches — free, instant, no signup.

Check my email — free

No signup · Under 2 seconds · Never stored

Was my email hacked?

Check if your email is compromised in seconds. Free, private, no signup. Scan millions of breach records across 1034+ known breaches.

Check my email now — it's free

No signup required · Results in under 5 seconds · Your data is never stored