Last.fm was hacked, confirmed by Last.fm on 6/8/2012

Last.fm has updated their blog indicating that there was a breach and have confirmed that they're forcing password changes. The entire password database has been floating around for around a year it appears.
If you have a Last.fm account, we strongly suggest that you immediately:


  1. Change your Last.fm password
  2. Check if you have re-used your Last.fm password on any other websites and if so, change those passwords too.
    The LastPass security challenge can assist you in doing so.

Was *My* Last.fm Password Hacked?

If you would like to find out if your Last.fm password was one of the 2.5 million hashes that were publicly leaked, you can use the below tool. Please note that only harder to crack passwords were left uncracked and released, you should assume your password is cracked if you used Last.fm:

Sorry JavaScript is required to use this tool



Wait a Minute, Why Is This Tool Safe?

You already changed your password, right? You no longer use that old password anywhere else, right? If not please make sure you do that first. The above tool asks you to enter your Last.fm password, and then computes its MD5 hash and sends the result to LastPass.com to search the list of 2.5 million leaked password hashes. A hash is a mathematical function that is simple to perform in one direction, but very difficult to reverse. Meaning, the tool will convert your password into a series of characters in such a way that it will be very difficult to re-construct your original password.

Only the hash of your password will be sent to LastPass.com's servers, not your actual password. This hash will not be stored or logged at all. Please view source the page if you're technically inclined.

Note that if you used a simple password, such as one based on dictionary words, then it might be possible to reconstruct your original password. This is what all of the concern is about: the hashes of simple passwords can be easily reconstructed to reveal the original actual password.

I just want to see how it works...

It's fun to play with just how bad passwords are but use the LinkedIn one to play with those -- to see some of the crack passwords here try 19LastFM79 or 1;lastfm or my personal favorite lastfm31415926535

So what should I do now?

After you've updated your Last.fm password, start better managing your online life with LastPass. LastPass will help you store all of your usernames and passwords in one secure, central location. You can update old passwords with randomly generated ones, and let LastPass do the work of remembering them and filling them for you. You can download the LastPass addon here.

Do you have a LinkedIn or eHarmony account?

See if your eHarmony password was compromised. See if your LinkedIn password was compromised.