CRITICAL SEVERITYStreamingMusic

Deezer Data Breach

Deezer Music Streaming Service Breach (2019, Disclosed 2022): 244 Million User Records Including DOB & Location Exposed

Music streaming service.

Verified by ObscureIQ Intelligence

8.0Severity
244.8MRecords
8Fields
2019Year

ObscureIQ Breach Intelligence Scores
2.5
Breach Risk Index
10
Data Value
25
Market Recency
512
days
Since Breach

Risk Interpretation

Credential exposure enables account takeover and password reuse attacks. Behavioral data can support profiling and targeted phishing.

🎯 Impact & Downstream Threats

In November 2022 Deezer disclosed that a 2019 breach at a third-party data partner had exposed user data. The incident had gone undetected for three years before surfacing. The exposed dataset contained approximately 229 million records including email addresses, names, dates of birth, genders, geographic locations, IP addresses, spoken languages, and usernames. Deezer notified affected users and reported the incident to French data protection authority CNIL. No major settlement or significant r

Primary downstream threats:
  • Identity verification bypass using name + date of birth combination
  • Targeted phishing campaigns using exposed email addresses
  • Doxxing risk from physical address exposure

🔓 Threat Vectors

Identity verification bypass
Phishing, credential stuffing & account takeover
Name-based social engineering
Profile enrichment
Pattern-of-life analysis & physical surveillance
Geolocation & account flagging
Targeted phishing localization
Cross-platform tracking & credential stuffing

📋 Breach Intelligence

EntityDeezer
OrganizationPublic Company • France / Global
Breach Date2019-09-01
DBC Added2024-12-01
Added Date2024-12-01
Records~244.8M (244,839,508 records)
Attack VectorMisconfiguration
Data SubjectsUser
Breach PathwayDirect
SourceHave I Been Pwned / DataBreach.com / ObscureIQ
SensitivityStandard
Breach ID377;378
StatusConfirmed

📝 Executive Summary

Deezer, a French music streaming service, suffered a data breach originating from a 2019 incident involving a third-party data partner that retained user data after its contract with Deezer ended in 2020. The breach went undetected for roughly three years before the stolen data appeared for sale on a cybercrime forum in 2022, prompting Deezer to disclose the incident. Approximately 244.8 million user records were compromised in total, making it one of the largest breaches in the music streaming sector. The exposed data included full names, email addresses, dates of birth, genders, city and country of residence, IP addresses, usernames, and spoken languages. Deezer confirmed that no passwords or payment details were included. Even so, the combination of personal identifiers and behavioral data is enough to support convincing phishing attacks and targeted scams against affected users. Deezer reported the breach to France's data protection authority, CNIL, and published information about the incident on its support site. Some users criticized the company for not directly notifying individuals affected. The three-year gap between the original incident and its discovery raised questions about vendor oversight practices. Affected users should remain alert to phishing attempts that reference their personal details and consider whether their email address has been used across other accounts.

🏢 About Deezer

Deezer is a French music streaming service offering on-demand audio, podcasts, and radio through subscription and free ad-supported tiers. Founded in 2007 and headquartered in Paris, the company operates in more than 180 countries and has been listed on Euronext Paris since 2022. It competes with Spotify, Apple Music, and Amazon Music, with particular strength in French-speaking markets and parts of Africa and Latin America.

Platform | Music streaming services | Subscription-based streaming platform | Global
Public CompanyFrance / Globaldeezer.com

🗂 Why They Hold Your Data

Streaming platforms store user accounts, emails, passwords, subscription details, and behavioral data such as listening history and preferences.

📰 Recent Developments

Deezer went public on Euronext Paris via a SPAC merger in July 2022, though the listing was followed by a challenging period of revenue pressure and share price decline. The company has pursued partnerships with telecommunications carriers and content bundling arrangements to grow its subscriber base. It has maintained a focus on markets where Spotify's presence is less dominant.

🔍 Data Points Exposed

8 verified field types:
Email
Name;Dates of birth
Email
Genders
Geographic locations
IP addresses
Names
Spoken languages
Usernames

Exposure Categories

LocationGEO LOCS

Canonical Fields

date_of_birth, email_address, full_name, gender, geographic_locations, ip_address, spoken_language, username

🌐 Dark Web Verification

Confirmed
  • Dataset containing ~244.8M records identified in breach intelligence sources
  • Data indexed and searchable across breach notification platforms
  • Source: deezer.com-2019;Deezer Data Breach

🛡 Recommended Actions

⚠️ Do not assume this is low sensitivity.

1Freeze Your Credit
Place a credit freeze with Equifax, Experian, and TransUnion.
2Expect Targeted Phishing
Watch for emails referencing this breach. Verify through official channels.
3Enable MFA Everywhere
Enable multi-factor authentication on all accounts.
4Monitor Accounts
Watch for unauthorized activity on financial and personal accounts.
5Check Your Exposure
ObscureIQ clients: this breach is indexed in your profile.

Protect Yourself

Check If You’re Affected

Enter your email to check if your data appears in this breach.

Get Free Breach Alerts

Be the first to know when new breaches are disclosed.

High-Risk? Get an Exposure Audit

Full-spectrum exposure audits for executives and public figures.

Request Consultation

ObscureIQ Advisory

We combine proprietary dark web access with commercial and restricted breach intelligence to verify exposure and assess real-world risk.

If you are:
  • A public-facing individual
  • A high-profile executive
  • A customer of Deezer
  • Or concerned about credential reuse
Services
AuditsWipesThreat MonitoringTraining

Classification Tags

MisconfigurationStreamingMusicEmailDOB

Powered by the ObscureIQ Breach Intelligence Database

© 2026 ObscureIQ · All Rights Reserved · Data Licensing

Latest from ObscureIQ

Credit

What Is Credit Monitoring? And Do I Want It? (Answer: Not Really)

July 14, 2025
Every time there’s a major data breach, companies scramble to offer “free” credit monitoring. It sounds like a responsible move.…
breach economycredit freezecredit scoreequifaxexperian
Credible Threats

Lock Down Browsers. Wipe Employee Footprints. Win Breach Wars.

September 2, 2025
Lock Down Browsers. Wipe Employee Footprints. Win Breach Wars. Over 80% of security incidents now start in the browser. Chrome.…
brave browserbreachesbrowser exploitbrowserschrome
Analysis

Sextortion Spam

May 10, 2025
Sextortion scams aren’t new, but they remain one of the most effective forms of cyber-enabled fraud. These scams don’t rely…
bitcoindeadlinefeargoogle maps apiransom