Home OSINT News Signals
CYBER

Raaga - 10,225,145 breached accounts

🕓 1 min read

EXCLUSIVE: 10 MILLION MUSIC FANS HACKED AS MAJOR STREAMING SERVICE DATA DUMPED ON DARK WEB

A massive cybersecurity incident has struck the popular Indian music platform Raaga, with a staggering 10.2 million user records now being hawked on hacking forums. This is not a minor data breach; it is a full-scale digital heist exposing emails, names, genders, ages, and critically, passwords stored with dangerously weak MD5 encryption without a salt. This vulnerability made decrypting them trivial for attackers.

The breach, allegedly occurring in December 2025, showcases a perfect storm of security failures. Using an unsalted MD5 hash for passwords in this era is gross negligence, effectively handing the keys to the kingdom to threat actors. This data is a goldmine for follow-on phishing campaigns, credential stuffing attacks, and identity theft, putting millions at immediate risk far beyond their music accounts.

"Storing passwords like this in 2025 is like locking a bank vault with a piece of string," one furious cybersecurity expert told us. "This wasn't a sophisticated zero-day exploit; this was an open door. The criminals likely used known techniques to crack these hashes and are now selling the clean data for ransomware operations or to fund crypto schemes."

Every user must act NOW. If you had a Raaga account, you must change that password on EVERY service where you've used it. Enable two-factor authentication (2FA) universally. This incident proves you cannot reuse passwords. Consider a reputable password manager to generate and store unique, complex secrets for every account. Your digital life depends on it.

This breach will ripple through the dark web for years, fueling countless secondary attacks. It serves as a brutal warning to all companies: blockchain-level security thinking is needed for basic user data, or you will be the next headline. For Raaga's users, the music has stopped, and the sirens are blaring.

Check your email. Change your passwords. Assume you are compromised. The concert is over, and the hackers are now on stage.

Telegram X LinkedIn
Back to News