CRITICAL SEVERITYStreamingMusic

Raaga Data Breach

Raaga Indian Music Streaming Platform Breach (2025): 10.2 Million User Accounts Including Passwords & DOB Exposed

Music streaming and entertainment platform focused on Indian content.

Verified by ObscureIQ Intelligence

8.5Severity
10.2MRecords
7Fields
2025Year

ObscureIQ Breach Intelligence Scores
6.3
Breach Risk Index
10
Data Value
60
Market Recency
98
days
Since Breach

Risk Interpretation

Primary risks include account takeover, phishing, and interest-based profiling. Listening behavior can also reveal language, culture, and identity signals that improve targeting.

🎯 Impact & Downstream Threats

The institutional impact on Raaga is significant given the breach's scale, the platform's regulatory exposure under India's DPDP Act, and the security-community concerns about the deprecated cryptographic practices documented in the leaked dataset. Raaga has confirmed the breach but has not detailed remediation measures or notification practices. The reputational impact concentrates within the Indian music streaming category, where Raaga has historically been one of several major regional music

Primary downstream threats:
  • Credential stuffing against reused passwords across other platforms
  • Identity verification bypass using name + date of birth combination
  • Targeted phishing campaigns using exposed email addresses
  • Doxxing risk from physical address exposure

🔓 Threat Vectors

Profile enrichment
Identity verification bypass
Phishing, credential stuffing & account takeover
Name-based social engineering
Pattern-of-life analysis & physical surveillance
Credential stuffing & account takeover

📋 Breach Intelligence

EntityRaaga
OrganizationPrivate Company • India / Global
Breach Date2025-12-01
HIBP Added2026-01-19
Records~10.2M (10,200,000 records)
Attack VectorUnknown
Threat ActorUnknown
Data SubjectsUser
Breach PathwayDirect
SourceHave I Been Pwned / ObscureIQ
SensitivityStandard
Breach ID1121.0
StatusConfirmed

📝 Executive Summary

Raaga, an India-based music streaming and entertainment platform focused on Indian-language audio content, suffered a data breach in approximately mid-December 2025 when threat actors gained unauthorized access to Raaga's systems and exfiltrated a database containing personal information for over 10.2 million user accounts. The data was subsequently posted for sale on an underground hacking forum. The breach was indexed by Have I Been Pwned on January 19, 2026 and covered by Indian and international cybersecurity media in January 2026. Raaga has publicly confirmed the breach but has not detailed the original compromise vector, the specific vulnerability exploited, or post-breach security improvements.

The breach affected approximately 10,225,145 unique user accounts based on records indexed by breach-tracking services. Compromised fields included names, email addresses, gender information, ages and (in some cases) full dates of birth, postcodes for geographic locations, and passwords stored as unsalted MD5 hashes. The unsalted MD5 password storage represents a particularly severe failure mode because MD5 has been recognized as cryptographically broken for over a decade, and the absence of salting allows attackers to use precomputed rainbow tables to rapidly recover the underlying password values. Modern industry standards including bcrypt, scrypt, and Argon2 have been recommended replacements for over a decade.

For affected users, the practical risk profile is severe and long-lasting because the unsalted MD5 password storage means the original password values can be recovered for many users with only modest computational effort. The combination of name, email address, date of birth, gender, and postcode supports targeted phishing and identity-verification bypass attempts at financial institutions, Indian government services where date of birth and contact information may be used for identity confirmation, and other accounts. Inclusion in the dataset confirms a Raaga subscription or account relationship and may support culturally-targeted phishing referencing Indian music, regional language preferences inferred from listening history, or specific Raaga-platform features. Affected users should change any reused passwords immediately on all other accounts, enable two-factor authentication where available, treat unsolicited contact referencing Raaga or related Indian-language services with caution, and remain alert to phishing campaigns referencing real demographic details that may have been included in the stolen dataset.

🏢 About Raaga

Raaga is an India-based music streaming and entertainment platform focused on Indian language content including Hindi, Tamil, Telugu, Malayalam, Kannada, Bengali, Punjabi, and other regional Indian language music. Headquartered in India and operating globally at raaga.com, the platform serves a substantial international user base including the Indian diaspora across North America, Europe, the Gulf region, and Southeast Asia. As an account-based music streaming platform, Raaga maintains user account data including names, email addresses, demographic information, geographic location, listening history, subscription billing records, and login credentials tied to audio consumption and recommendation features.

Platform | Music streaming services | Digital audio platform | India / Global
Private CompanyIndia / Globalraaga.com

🗂 Why They Hold Your Data

Music-streaming platforms collect user accounts, emails, subscription records, listening history, device identifiers, and engagement data tied to audio consumption and recommendation systems.

📰 Recent Developments

Raaga has confirmed the December 2025 breach in public statements following the data's appearance on hacking forums in January 2026 and broader industry coverage. The breach has been the subject of significant security-research commentary because of Raaga's use of unsalted MD5 password storage, which has been characterized as a deprecated cryptographic method that the security community abandoned over a decade before the breach. Raaga has not publicly detailed the discovery timeline, the specific vulnerability that enabled the compromise, the timing of user notifications, or post-breach security improvements. The breach is subject to oversight under India's Digital Personal Data Protection Act 2023 (DPDP Act), which carries materially higher potential penalties than earlier Indian data-protection frameworks.

🔍 Data Points Exposed

7 verified field types:
Ages
Dates of birth
Email
Genders
Geographic locations
Names
Passwords

Exposure Categories

LocationGEO LOCS

Canonical Fields

age, date_of_birth, email_address, full_name, gender, geographic_locations, password

🌐 Dark Web Verification

Confirmed
  • Dataset containing ~10.2M records identified in breach intelligence sources
  • Data indexed and searchable across breach notification platforms
  • Source: Raaga Data Breach

🛡 Recommended Actions

⚠️ Do not assume this is low sensitivity.

1Freeze Your Credit
Place a credit freeze with Equifax, Experian, and TransUnion.
2Expect Targeted Phishing
Watch for emails referencing this breach. Verify through official channels.
3Enable MFA Everywhere
Enable multi-factor authentication on all accounts.
4Monitor Accounts
Watch for unauthorized activity on financial and personal accounts.
5Check Your Exposure
ObscureIQ clients: this breach is indexed in your profile.

Protect Yourself

Check If You’re Affected

Enter your email to check if your data appears in this breach.

Get Free Breach Alerts

Be the first to know when new breaches are disclosed.

High-Risk? Get an Exposure Audit

Full-spectrum exposure audits for executives and public figures.

Request Consultation

ObscureIQ Advisory

We combine proprietary dark web access with commercial and restricted breach intelligence to verify exposure and assess real-world risk.

If you are:
  • A public-facing individual
  • A high-profile executive
  • A customer of Raaga
  • Or concerned about credential reuse
Services
AuditsWipesThreat MonitoringTraining

Classification Tags

StreamingMusicEmailPasswordsDOB

Powered by the ObscureIQ Breach Intelligence Database

© 2026 ObscureIQ · All Rights Reserved · Data Licensing

Latest from ObscureIQ

Credit

What Is Credit Monitoring? And Do I Want It? (Answer: Not Really)

July 14, 2025
Every time there’s a major data breach, companies scramble to offer “free” credit monitoring. It sounds like a responsible move.…
breach economycredit freezecredit scoreequifaxexperian
Credible Threats

Lock Down Browsers. Wipe Employee Footprints. Win Breach Wars.

September 2, 2025
Lock Down Browsers. Wipe Employee Footprints. Win Breach Wars. Over 80% of security incidents now start in the browser. Chrome.…
brave browserbreachesbrowser exploitbrowserschrome
Analysis

Sextortion Spam

May 10, 2025
Sextortion scams aren’t new, but they remain one of the most effective forms of cyber-enabled fraud. These scams don’t rely…
bitcoindeadlinefeargoogle maps apiransom