include
Answered

Security breach

  • 3 January 2023
  • 4 replies
  • 130 views

Hello, according to the Firefox monitor there has been a security breach at the Deezer website on the 22nd of April in 2019. Firefox has its information from https://www.haveibeenpwned.com/.

It apparently took very long to discover this. The breacht revealed ip-adresses, e-mail adresses, date of birth and other personal data.

Did I mis information about this from Deezer or has this just now been revealed? I would very much like to know what is the truth about this information. 

icon

Best answer by Jaime. 6 January 2023, 11:23

View original

4 replies

Userlevel 7
Badge +7

Hello @Erwin62 As you may have noted, the data breach occurred in 2019, not in 2022. Immediately after learning of the data breach in November 2022, we contacted the CNIL (Commission Nationale de l'Informatique et des Libertés), with whom we have been working ever since, particularly with regard to the communication we must make to users.
In order not to wait for the outcome of this work, we published an article on our support site to inform the users concerned about the data leak. We are currently finalizing our user communication with the CNIL, which will be sent to those affected by the breach.

The data included in the sample are mainly email address, date of birth (usually in the form "01-01-XXXX" since we only ask for age), name (usually a pseudonym), gender, language used, country, general information regarding subscription, and communication preferences (opt-in/opt-out). The sample does not contain any sensitive data, passwords, payment data, service usage data (such as listening history), geolocation data, or data that would allow for the description of the user habits. Furthermore, it is important to note that this is old data, dating back more than three years.

Hello Jaime, thank you for you reply. As you will have read I was aware of the year in wich this breach occured an mentioned this in my question. I apperently missed communication about this. 

I understand now that there will be further information to come. Thank you for the answer

Hello, i have rejoined Deezer so that I can now delete all details and delete my account.  I joined up many years ago but then left it, and thought I had deleted the app. 

But two days ago I received an email from McAfee Internet Security saying that my details were now on the Dark Web,  thanks to the Security breach in September 2019. I wasn't even aware that I had a live account.  To say that I was horrified is an understatement,  knowing of the very dangerous activities found on the Dark Web. I just wanted to make people aware of this. 

Userlevel 7
Badge +7

@Sylvia.Millam I am sorry to hear that.
Please get in touch with our Deezer Support Team and one of our agents will check on the system to make sure that any account and personal data is permanently deleted.
Thanks

Reply