Deezer 2019 Data Breach

Deezer Music Streaming Service Breach (2019, Disclosed 2022): 244 Million User Records Including DOB & Location Exposed

Platform · Music streaming services · Subscription-based streaming platform · Global

Deezer Music Streaming Service Breach (2019, Disclosed 2022): 244 Million User Records Including DOB & Location Exposed

Music streaming service.

Confirmed · ObscureIQ Intelligence
Breach Risk Index i
34/100
Lower riskHigher risk
Moderate: notable exposure with meaningful misuse potential.
Data Sensitivity i
Standard
Exposed data is largely lower-sensitivity. Standard identity-protection precautions are advised.
244.8MRecords
2019Year

The Breach Risk Index (BRI) is a proprietary 0–100 score rating how dangerous a breach is right now, based on how recently the data has been circulating on the dark web and how valuable it is to attackers.

Classification Tags
Cloud MisconfigurationStreamingUsers2019

Breach Summary

Deezer, a French music streaming service, suffered a data breach originating from a 2019 incident involving a third-party data partner that retained user data after its contract with Deezer ended in 2020. The breach went undetected for roughly three years before the stolen data appeared for sale on a cybercrime forum in 2022, prompting Deezer to disclose the incident. Approximately 244.8 million user records were compromised in total, making it one of the largest breaches in the music streaming sector. The exposed data included full names, email addresses, dates of birth, genders, city and country of residence, IP addresses, usernames, and spoken languages. Deezer confirmed that no passwords or payment details were included. Even so, the combination of personal identifiers and behavioral data is enough to support convincing phishing attacks and targeted scams against affected users. Deezer reported the breach to France's data protection authority, CNIL, and published information about the incident on its support site. Some users criticized the company for not directly notifying individuals affected. The three-year gap between the original incident and its discovery raised questions about vendor oversight practices. Affected users should remain alert to phishing attempts that reference their personal details and consider whether their email address has been used across other accounts.

Full threat analysis, exploitation vectors, and principal guidance below.

10 additional sections · verified field analysis · defensive doctrine

Querying breach corpus…
Cross-referencing exposed field types…
Resolving threat-actor attribution…
Compiling principal risk advisory…

244.8M records analyzed

About Deezer

Deezer is a French music streaming service offering on-demand audio, podcasts, and radio through subscription and free ad-supported tiers. Founded in 2007 and headquartered in Paris, the company operates in more than 180 countries and has been listed on Euronext Paris since 2022. It competes with Spotify, Apple Music, and Amazon Music, with particular strength in French-speaking markets and parts of Africa and Latin America.

Why They Hold Your Data

Streaming platforms store user accounts, emails, passwords, subscription details, and behavioral data such as listening history and preferences.

Recent Developments

Deezer went public on Euronext Paris via a SPAC merger in July 2022, though the listing was followed by a challenging period of revenue pressure and share price decline. The company has pursued partnerships with telecommunications carriers and content bundling arrangements to grow its subscriber base. It has maintained a focus on markets where Spotify's presence is less dominant.

Data Points Exposed

8 verified field types
Date of Birth High
Email Address
Full Name
Gender
Geographic location
IP Address
Spoken Language
Username

Breach Impact

In November 2022 Deezer disclosed that a 2019 breach at a third-party data partner had exposed user data. The incident had gone undetected for three years before surfacing. The exposed dataset contained approximately 229 million records including email addresses, names, dates of birth, genders, geographic locations, IP addresses, spoken languages, and usernames. Deezer notified affected users and reported the incident to French data protection authority CNIL. No major settlement or significant regulatory enforcement action specific to this breach has been prominently documented, though the three-year detection gap drew attention to vendor oversight practices.

Exploitation & Downstream Threats

• Identity verification bypass using name + date of birth combination | • Targeted phishing campaigns using exposed email addresses | • Doxxing risk from physical address exposure

Principal Risk Advisory

What this means for a principal

A consumer-service breach: contact and account data supports phishing, account takeover and profile enrichment. For a high-profile principal the main risk is credible impersonation and enrichment of existing exposure.

What You Should Do

  1. Do not use unofficial 'am I affected' lookups; several are themselves harvesting operations.

How ObscureIQ Can Help

  1. Corpus confirmation: determine whether and where the principal (plus household and staff) appear in this dataset and which specific fields are exposed for them.
  2. Exposure mapping: cross-reference the exposed identifiers against broker-available data to size and prioritize the principal's wider footprint.
  3. ThreatWatch tuned to this incident's identifiers and misuse pattern (impersonation and targeting patterns, not generic credential monitoring).

Protect Yourself

Check If You're Affected

Enter your email to check whether your data appears in this breach. We’ll send a 6-digit code to confirm it’s your address.

Get Free Breach Alerts

Be the first to know when new breaches are disclosed. Free forever — confirm your email with a 6-digit code.

High-Risk? Get an Exposure Audit

Executives, public figures, and high-visibility operators can receive tailored exposure intelligence and hardening guidance.

Request Consultation