External Breached Credentials: 8Tracks

Threat Level: Low
Threat Type: External Account Breach
Advisory Date: 07/13/2023

Description

In June 2017, the online playlists service known as 8Tracks suffered a data breach which impacted 18 million accounts. The data was consequently published should be expected to become freely available. The records in the breach included usernames, email addresses and hashes of passwords.

We have no indication at this time that any user passwords have been compromised, but we strongly recommend that all users reset their passwords as soon as possible.

Although the risk of passwords being cracked is relatively small (unless you had chosen a particularly poor password), 8tracks sensibly recommends that users change their passwords on other sites as well, if they were reusing the same password.

Impact

If 8tracks account holders used the same password on 8tracks as with other services, there is risk.  For example, if you used the same or similar password on 8tracks as for University of Regina accounts, online banking, or other accounts, accounts with the same or similar passwords may also be at risk. If you did reuse passwords across accounts, it is recommended that you change your passwords as soon as possible.

Resolution

As with any account credential, several precautions should be taken:
-Choose a totally unique password for each account, website, or service.
-Choose passwords to include a mix of letters, numbers, and symbols.
-Make your password long - the longer the better.
-Set up Two-Factor Authentication for all accounts which support it.

To change your University of Regina password, please visit: https://novapp.cc.uregina.ca/perl/chpass.pl .

For guidelines on creating strong passwords, please visit: http://www.uregina.ca/is/security/resources/resource-password.html .

Individual uregina.ca account holders will be notified via emailed.

Resources

For further resources on this password breach, please see: 

8tracks breach yields data on 18M accounts

8tracks Hacked: 18 Million User Account Details Stolen

Please note that the data included in this notification was acquired from an external source. The University of Regina makes no representations, guarantees, or warranties as to the accuracy, completeness, currency, or suitability of the information provided in this notification. The information is provided "as-is” for preventive and corrective purposes.

Please contact the University of Regina IT Support Centre if you have any questions or require assistance:

Webform http://www.uregina.ca/is/forms/ticket.html
Email IT.Support@uregina.ca
Phone 306-585-4685