Deezer — 229 Million Records a Partner Was Supposed to Have Deleted (2019, disclosed 2022)
If you have an account with Deezer, here’s what’s now in circulation.
The music service was not breached. A third-party partner kept a mid-2019 backup after its contract ended, and that copy was sold and redistributed in late 2022. No passwords — but three and a half years passed between exposure and disclosure.
What happened
In late 2022 the music streaming service Deezer disclosed a breach affecting more than 240 million customers, of which 229,037,936 unique email addresses reached the HIBP catalogue. The data did not come from Deezer's own systems. It came from a mid-2019 backup held by a third-party partner, which was subsequently sold and then broadly redistributed on a hacking forum.
Deezer's account of it is that the provider retained the data after the contract between them was terminated, contrary to its obligations and despite steps Deezer took to have the data destroyed. That is why the dataset is dated 2019 while the disclosure is dated 2022.
The gap is the finding
Set the record count aside for a moment. The interesting number on this page is three and a half years — the interval between a copy of your data leaving the control of the company you trusted and anyone telling you about it.
Nothing failed at Deezer in the way people picture a breach. There was no intrusion, no ransomware group, no extortion. A vendor simply did not delete something when it said it would, and no mechanism existed to notice. This is the most common shape of large modern data loss and the least visible, because the company whose name is on the page often genuinely did not know.
It is also the reason a one-time breach check ages badly. Your exposure in 2019 was already real; it just was not knowable until 2022.
What was and was not exposed
No passwords were in this data. There is nothing to rotate, and Deezer account security is not what is at stake.
What is in it: email addresses, names, usernames, dates of birth, genders, geographic location, IP addresses and spoken languages. Spoken language is an unusual field to see leaked, and worth a moment — combined with location it is a reliable indicator of diaspora communities, which is exactly the targeting granularity that fraud campaigns and state-aligned harassment operations look for. It also lets a phishing campaign arrive in the recipient's first language, which measurably raises its success rate.
The identity-chain implication
Streaming accounts are usually registered with a person's primary personal email — the one attached to the phone, the bank and the recovery flow — because they are set up for convenience rather than compartmentalised. That makes a streaming dataset an unusually clean map from primary email to real name and birthday.
Deezer records join the chain as confirmation rather than discovery: they take an attacker's guess that an address belongs to a particular person and turn it into a fact, with a birthday attached.
What to do now
What You Should Do
- Check every address you have ever used for streaming signups, not just your current one — this data is from 2019
- Stop treating date of birth as a secret: it is in this dataset and dozens like it, so any service using it to verify you is not verifying anything
- Be sceptical of well-written phishing in your first language referencing a music service — the dataset supports exactly that targeting
- Ask for deletion, not just closure, when you leave a service — this breach exists because a deletion obligation went unverified
- Use continuous monitoring rather than a one-time check, since this exposure was real for three years before it was knowable
What the free scan actually returns
Found on people-search siteswe remove these
These listings are live, public, and legal to remove. That’s what a Deep Sweep buys.
Found in breach recordsverifiedreported — unverified
Each record is labeled: confirmed breach data, or an attacker’s claim no one has verified.
Leaked data cannot be deleted from the internet — anyone claiming otherwise is lying. Broker listings can be removed. We do the second, and show you exactly what to fix from the first.
Report details & sourcing
Related breaches
Verifications.io — 763 Million Email Records Left on an Open Database (2019)
An email-validation firm most people had never heard of left 763 million records in a MongoDB instan…
Rockstar Games 78 Million Records via Snowflake/Anodot — April 2026
ShinyHunters compromised Rockstar Games via a third-party Snowflake/Anodot analytics instance, exfil…
Facebook — 509 Million Phone Numbers Tied to Real Names (2019, published 2021)
Roughly 20% of Facebook made freely downloadable in April 2021, scraped through a contact-import wea…