A 60GB CSV file containing personal information, including that of the 228 million Deezer subscribers, was shared on a forum by a hacker.
Deezer claims that hackers broke into one of their third-party partners and grabbed a snapshot of customer data.
They advised customers to implement two-factor authentication and update their Deezer platform passwords.
Source: https://purplesec.us/security-insights/deezer-data-leak-228-million-users/
TPRM report: https://scoringcyber.rankiteo.com/company/deezer
"id": "dee3257823",
"linkid": "deezer",
"type": "Data Leak",
"date": "11/2022",
"severity": "60",
"impact": "4",
"explanation": "Attack with significant impact with customers data leaks"
{'affected_entities': [{'customers_affected': '228 million',
'industry': 'Music Streaming',
'name': 'Deezer',
'type': 'Company'}],
'attack_vector': 'Third-Party Compromise',
'customer_advisories': ['Implement two-factor authentication',
'Update Deezer platform passwords'],
'data_breach': {'data_exfiltration': 'Yes',
'file_types_exposed': 'CSV',
'number_of_records_exposed': '228 million',
'personally_identifiable_information': 'Yes',
'type_of_data_compromised': 'Personal Information'},
'description': 'A 60GB CSV file containing personal information, including '
'that of the 228 million Deezer subscribers, was shared on a '
'forum by a hacker. Deezer claims that hackers broke into one '
'of their third-party partners and grabbed a snapshot of '
'customer data. They advised customers to implement two-factor '
'authentication and update their Deezer platform passwords.',
'impact': {'data_compromised': ['Personal Information']},
'initial_access_broker': {'entry_point': 'Third-Party Partner'},
'motivation': 'Data Theft',
'post_incident_analysis': {'root_causes': 'Third-Party Partner Compromise'},
'recommendations': ['Implement two-factor authentication',
'Update Deezer platform passwords'],
'response': {'remediation_measures': ['Advised customers to implement '
'two-factor authentication',
'Advised customers to update their '
'Deezer platform passwords']},
'threat_actor': 'Unknown Hacker',
'title': 'Deezer Data Breach',
'type': 'Data Breach'}