About 359 million email addresses sat in the MySpace credential file stolen around 2008 and sold in 2016 — usernames plus weak password hashes, not a modern scrape. Check whether your address is in that file, then treat any reused password as the first job.
Quick answer — was MySpace breached?
Yes — this page is the ~2008 MySpace password-database theft that was offered for sale in May 2016, about 359 million unique emails with usernames and SHA-1 password hashes. It is not a later Facebook- or Twitter-style scrape. A match means your address appeared in that credential file. Check if you were affected.
What happened in the MySpace data breach?
This catalog row is the old MySpace credential file — emails, usernames, and weakly stored passwords — not a later social-media scrape. The theft itself was never given a precise company date. Independent analysis of the circulating file puts it around mid-2008 to early 2009. In May 2016 a seller listed almost 360 million accounts on a dark-web market. This lookup lists about 359.4 million unique email addresses.
The passwords were stored as unsalted SHA-1 hashes of only the first ten characters, after converting the password to lowercase. That is not modern hashing. Identical short passwords produced identical hashes, and case and anything past character ten did not count. People who had left MySpace still reused those strings on email and shopping sites. Deleting the MySpace profile later did not pull the 2016 sale back.
Contemporaneous counts sometimes said about 427 million password hashes because some rows carried a second password. The unique-email count in this catalog is about 359.4 million. MySpace said accounts created before a 11 June 2013 platform change were the ones at risk, and it invalidated those old passwords. That closes MySpace. It does not close any other site that still shared the string. Learn more about what a data breach means for you.
Why was the MySpace breach so dangerous?
The passwords were stored as unsalted SHA-1 hashes of only the first ten characters, after converting the password to lowercase. That is not modern hashing. Identical short passwords produced identical hashes, and case and anything past character ten did not count. People who had left MySpace still reused those strings on email and shopping sites. Deleting the MySpace profile later did not pull the 2016 sale back.
Yes, if that mid-2000s MySpace password was ever reused and has not been changed. The file is old, widely copied, and still useful for credential stuffing. A unique password plus an authenticator-app second factor is what ages this incident out of your life. Closing or ignoring MySpace does not retire the same string on email.check whether your email was exposed in this breach.
What data was stolen in the MySpace breach?
Email addresses — used for phishing attacks and credential stuffing against your other accounts
Passwords — can be used to access your accounts directly or cracked to reveal your actual password
Usernames — used to build profiles and target you with personalised scams
Timeline of the MySpace breach
Mid-2008 to early 2009
Best public estimate for when the MySpace credential file was taken, based on independent analysis of email-provider mix and account-creation dates in the later sale
2008–2016
The file is held or traded privately; MySpace users are not given a public notice in that window
May 2016
A seller lists almost 360 million MySpace accounts on a dark-web market — emails, usernames, and SHA-1 password hashes
31 May 2016
MySpace confirms stolen usernames and passwords for accounts created before 11 June 2013 and invalidates those old credentials
31 May 2016
Independent write-up of the file: unsalted SHA-1 of the first ten lowercase password characters; about 359.4 million unique emails
2016–2026
Copies remain in credential-stuffing lists; leftover reused passwords from the file still unlock other sites
Is the MySpace breach still dangerous in 2026?
Yes, if that mid-2000s MySpace password was ever reused and has not been changed. The file is old, widely copied, and still useful for credential stuffing. A unique password plus an authenticator-app second factor is what ages this incident out of your life. Closing or ignoring MySpace does not retire the same string on email.
Email addresses from a 2008-era social network do not expire as phishing targets. Unique passwords and two-factor authentication are the work. Learn how long stolen data stays dangerous.
How is this different from later social scrapes?
A password-database theft and a public-profile scrape are different failures. This row is the first kind: attackers copied MySpace stored logins. The circulating file had an internal ID, an email, a username, and one or two password hashes. It did not include the later mix of phone numbers, bios, and follower counts that appear in 2020s social scrapes.
The hashes themselves were unusually weak even for 2008. Researchers who opened the 2016 sale described SHA-1 of the first ten characters, forced to lowercase, with no salt. That is why leftover reuse still matters in 2026: a cracked short password is a working login anywhere it was repeated.
Other 2016 sales — LinkedIn from 2012, Tumblr from 2013 — were listed in the same season. They are separate catalog rows. Do not fold them into this match.
- This row — ~2008 MySpace credentials sold in 2016. Emails, usernames, weak password hashes.
- Later social scrapes — phones and public profile fields. Different rows, different playbook.
- A match here is the password playbook. Fix reuse. Do not hunt for a live MySpace session as the whole job.
What does an EmailLeaked MySpace match mean?
If your address is in the 2008-era credential file, EmailLeaked shows a named MySpace match the same way it shows any other named incident. The row is a lookup against industry-standard breach data sources. We do not claim an exclusive copy of the 2016 sale, and we do not crawl hidden markets live.
A match is not proof someone opened a MySpace page this week. It is evidence that the address — and typically a weak password hash from that era — appeared in a file that has been public since 2016. A miss is a snapshot of the records we can search today. We do not keep the address you type into the checker. Hosting logs and a privacy-oriented analytics beacon can still record that the page was visited.
If you want the response order in one place, use what to do after a data breach. If you want to test a reused password without sending the full password, use the password leak checker. For a second public index, see free data breach checkers.
What to do if your email was in the MySpace breach
Confirm the match and what was listed
Run the email check if you need the named incidents in one list. This MySpace row lists emails, usernames, and passwords. That is the password playbook, not a scrape playbook.
Check this email — freeTreat any reused password as public
Change the password on every site that shared the old MySpace string — starting with email. Then check whether that password appears in known leaks without sending the password itself.
Turn on two-factor authentication
Start with email. An authenticator app is stronger than a text-message code. A stuffing bot that has the 2008-era password still fails if the second factor is not sitting on a leaked phone number.
Follow the after-breach playbook
Use the first-hour and 24-hour lists, then the password playbook. Walk the account security checklist so recovery email, sessions, and leftover logins get a pass.
Open the after-breach playbookCompare how public checkers differ
A second lookup does not change the 2016 sale. It can show you how different public indexes present the same named incident.
Read the checker comparisonClose leftover MySpace if you still have a login
Deletion does not unsay the 2016 sale. It stops an old social login from sitting around. If the profile is already gone, still retire any password you reused there.
Browse delete-account guidesFrequently asked about the MySpace breach
What happened in the MySpace data breach this page covers?
How were MySpace passwords stored?
Why do some articles say 427 million passwords?
I deleted my MySpace account years ago — am I still at risk?
How does EmailLeaked show a MySpace match?
Is the MySpace breach still dangerous in 2026?
How this breach page is reviewed
Breach pages are built from structured breach records and reviewed for practical risk guidance by EmailLeaked. Risk labels reflect exposed data types and are intended to help readers prioritise action.
Sources
Last updated: September 2026
Other major breaches
Was your email in this breach?
Check if your email appeared in the MySpace breach and 1033+ other known breaches — free, instant, no signup.
Check my email — freeWas my email hacked?
Check if your email is compromised in seconds. Free, private, no signup. Scan millions of breach records across 1034+ known breaches.
Check my email now — it's freeNo signup required · Results in under 5 seconds · Your data is never stored