Skip to main content
One Hit Wonder
January 2, 2023
Answered

Tell me about your data breach

  • January 2, 2023
  • 17 replies
  • 2695 views

...the one that happened to Deezer in 2019 but has only recently been reported by HaveIBeenPwned. I can’t seem to find anything on this site about it. I haven’t received email from Deezer about it. Yet it evidently affects 204 million Deezer customers.

    This topic has been closed for comments - the content may no longer be relevant or up-to-date, so please search for keywords so that you can find a newer post or look below for a direct link
    Best answer by Jaime.Deezer

    Immediately after learning of the data breach in November 2022, we contacted the CNIL (Commission Nationale de l'Informatique et des Libertés), with whom we have been working ever since, particularly with regard to the communication we must make to users. In order not to wait for the outcome of this work, we published an article on our support site to inform the users concerned about the data leak. We are currently finalizing our user communication with the CNIL, which will be sent to those affected by the breach.
    The data included in the sample are mainly email address, date of birth (usually in the form "01-01-XXXX" since we only ask for age), name (usually a pseudonym), gender, language used, country, general information regarding subscription, and communication preferences (opt-in/opt-out). The sample does not contain any sensitive data, passwords, payment data, service usage data (such as listening history), geolocation data, or data that would allow for the description of the user habits. Furthermore, it is important to note that this is old data, dating back more than three years.
    As far as Deezer's systems are concerned, their security is not compromised and, of course, we will continue to enhance our capabilities to ensure their protection and the protection of our users' data, including vulnerability scans and penetration tests.

    17 replies

    Roadie
    January 6, 2023

    This is even more -stupid- (sorry, can not find a better word). By not communicating and re-assuring your users, your customers, you are building fear and anxiety and diminishing trust. You do not show you are in control.

    Beside, I am not sure how much what you say should be taken for granted. I have, myself, worked with the CNIL as well, they do not recommend or tell you what to do (pro active). They evaluate what you have done and if it was enough (reactive).

     

    I think you made, at least a big communication mistake.

     

    Learning this from security monitoring site such as HaveIBeenPwnd makes you look like clueless and careless about your own users and data.

     

    I stand to my initial statement. If, when, I receive an answer from the support about this and it is not satisfying, I will fill a complain with the CNIL and I would recommend the same to anyone who is not sure about the way you have handle this incident. If it can not change what happened and how you handled the incident anymore, it may prevent Deezer from doing the same type of mistake again.

    The whole purpose of GDPR is to let user deal with their data and keep them in control. You patonize your customer and told them they do not need to know… which, by the way, is interetsing as your communication suggested to change your passwrod...don’t you think, then, this should have been sent to said users ??

     

    Let’s be serious.

    barblessAuthor
    One Hit Wonder
    January 6, 2023

    @Jaime. thank you for bringing what appears to be an “official” perspective to this discussion.

    What your message describes is a compliance-focused security program, which is the bottom of the barrel. Working with compliance agencies to find out what, as you say above, they require that Deezer must do at some point in the increasingly distant future for something that happened in the distant past. A hallmark of this approach is for customers to see communications that originated in Legal or Communications, not Security. That communication, whenever it gets here, likely will check all the compliance boxes. And, like your message or the one already posted in Support, will leave your customers questioning at best, seething - or gone, like me! - at worst.

    A better alternative at this point is to pose the “how should this best be handled” question to your Security team (you have one, right?), and, if they have been properly funded and trained, to follow their recommendation.

    Hitmaker
    January 15, 2023

    Yeah, I’ve just started receiving pharmacy spam from “Canada RX”. I know it is from this breach as the email is a unique (random) email address. How about not giving your user’s data to 3rd parties Deezer?

    amoraluv
    Rising Star
    Rising Star
    February 2, 2023

    I just got an alert that Deezer had a data breach and my info was found on the dark web. 1/20/2023

    `@`~~
    Hitmaker
    February 3, 2023

    Yea, Deezer botched the communication. They damaged their credibility with how they report to customers. So people are right to worry about “what about the next breach?”

    But as a practical matter, I’m not so worried about the breach itself.

    It happened in 2019, three or four years ago. The “horse was long out of the barn” when they discovered it in November 2022. See what I mean? Yea, they should have reported it within 72 hours. Absolutely they should have. But I don’t think it would have made any difference if they had, not with regard to the stolen data. Too late for that.  

    (I even wonder if there are any provisions or practices for long ago breaches. It could make some sense, as in, don’t get everyone in a tizzy if nothing can be done. Besides, in my mind, isn’t it normal for people to update their password regularly? And if you don’t, now you have a reason to do so. 

    We'll see what happens. 

    Rising Star
    March 9, 2023

    I setup my deezer account with a unique email address which is only used for deezer.

     

    Today I am getting spam from Brand Medicals-Express on that email address.

    Has there been another data breach?

    I will change my deezer registered email address and kill the existing as a precaution.

    Yula
    Deezer Staff
    Deezer Staff
    March 13, 2023
    (She/her) add your pronouns to your signature!