Back to Blog
high severity April 22, 2019 · 3 min read

Deezer — 229 Million Records a Partner Was Supposed to Have Deleted (2019, disclosed 2022)

If you have an account with Deezer, here’s what’s now in circulation.

The music service was not breached. A third-party partner kept a mid-2019 backup after its contract ended, and that copy was sold and redistributed in late 2022. No passwords — but three and a half years passed between exposure and disclosure.

A backup copy persisting after a contract ends

What happened

In late 2022 the music streaming service Deezer disclosed a breach affecting more than 240 million customers, of which 229,037,936 unique email addresses reached the HIBP catalogue. The data did not come from Deezer's own systems. It came from a mid-2019 backup held by a third-party partner, which was subsequently sold and then broadly redistributed on a hacking forum.

Caught in this breach?
You can’t unleak a breach. You can take away what it’s worth.
Deep Sweep shows you every leak tied to you and exactly what to change. Then it strips your name, address and family off the look-up sites that turn a leaked record into somebody knocking on your door — $29 one-time, includes 30 days of Protection. We write to 582 companies. No subscription to start.
Scan free, then Deep Sweep — $29 →
Not ready yet? Run a free breach check on this email
We’ll check it against 13.1B+ leaked records right now — no account needed. Continuous monitoring & alerts are part of Protection.

Deezer's account of it is that the provider retained the data after the contract between them was terminated, contrary to its obligations and despite steps Deezer took to have the data destroyed. That is why the dataset is dated 2019 while the disclosure is dated 2022.

The gap is the finding

Set the record count aside for a moment. The interesting number on this page is three and a half years — the interval between a copy of your data leaving the control of the company you trusted and anyone telling you about it.

Nothing failed at Deezer in the way people picture a breach. There was no intrusion, no ransomware group, no extortion. A vendor simply did not delete something when it said it would, and no mechanism existed to notice. This is the most common shape of large modern data loss and the least visible, because the company whose name is on the page often genuinely did not know.

It is also the reason a one-time breach check ages badly. Your exposure in 2019 was already real; it just was not knowable until 2022.

What was and was not exposed

No passwords were in this data. There is nothing to rotate, and Deezer account security is not what is at stake.

What is in it: email addresses, names, usernames, dates of birth, genders, geographic location, IP addresses and spoken languages. Spoken language is an unusual field to see leaked, and worth a moment — combined with location it is a reliable indicator of diaspora communities, which is exactly the targeting granularity that fraud campaigns and state-aligned harassment operations look for. It also lets a phishing campaign arrive in the recipient's first language, which measurably raises its success rate.

The identity-chain implication

Streaming accounts are usually registered with a person's primary personal email — the one attached to the phone, the bank and the recovery flow — because they are set up for convenience rather than compartmentalised. That makes a streaming dataset an unusually clean map from primary email to real name and birthday.

Deezer records join the chain as confirmation rather than discovery: they take an attacker's guess that an address belongs to a particular person and turn it into a fact, with a birthday attached.

What to do now

What You Should Do

  1. Check every address you have ever used for streaming signups, not just your current one — this data is from 2019
  2. Stop treating date of birth as a secret: it is in this dataset and dozens like it, so any service using it to verify you is not verifying anything
  3. Be sceptical of well-written phishing in your first language referencing a music service — the dataset supports exactly that targeting
  4. Ask for deletion, not just closure, when you leave a service — this breach exists because a deletion obligation went unverified
  5. Use continuous monitoring rather than a one-time check, since this exposure was real for three years before it was knowable

What the free scan actually returns

Sample resultyou@email.comIllustrative — not a real person

Found on people-search siteswe remove these

These listings are live, public, and legal to remove. That’s what a Deep Sweep buys.

value redacted in this sampleage, relatives, address historySpokeo
value redacted in this samplephone, household, property recordsBeenVerified
value redacted in this sample582 companies checked

Found in breach recordsverifiedreported — unverified

Each record is labeled: confirmed breach data, or an attacker’s claim no one has verified.

verifiedvalue redacted in this samplepassword + phone · 2024telecom breach
unverifiedvalue redacted in this sampleclaimed in ransomware listing · 2026leak-site claim

Leaked data cannot be deleted from the internet — anyone claiming otherwise is lying. Broker listings can be removed. We do the second, and show you exactly what to fix from the first.

Were you a Deezer customer?
Deezer is one breach. Your email is probably in others.
229.0M email addresses accounts were exposed here. Check whether yours is one — and find every other leak tied to the same address, in about 15 seconds. No account, no card.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

Report details & sourcing

Severity High
Disclosed April 22, 2019
Last reviewed July 22, 2026
Affected 229.0M email addresses
Data exposed Email addressesNamesUsernamesDates of birthGendersGeographic locationsIP addressesSpoken languages
Editorial & sourcing policy
GalaxyWarden is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data. Breach information is compiled from publicly accessible sources and threat-intelligence platforms, and is reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — see our content & takedown policy or write to support@galaxywarden.com.
Share this Post on X Reddit Email