The cracked passwords of around 7.5 million members of the DatPiff platform are being sold online , and users can check if they are affected by this data breach through the Have I Been Pwned service.
DatPiff is a popular mixtape hosting service used by more than 15 million users.
See also: Hackers used cloud video hosting service to steal credit card details

Member data breach
We don't know when the data breach took place, but the DatPiff database was initially sold privately and then publicly on hacking forumsin July 2020.
The stolen database contains 7,476,940 member records, which include email addresses, passwords, usernames, and security questions.
On November 30, 2021, another hacker began selling the DatPiff database again on the same hacking forum. However, this time, the passwords were dehashed and the passwords were displayed properly along with the email address.

Soon after, another threat actor released the database completely free of charge, allowing anyone to use the information.
The passwords in the database could be "cracked" because DatPiff hashed them with the MD5 algorithm, an old (1992) cryptographic hash function, which is considered obsolete and insecure.
See also: Broward Health: Data breach affects 1.3 million people
BleepingComputer was notified in December that a threat actor had compromised DatPiff using a vulnerability, which allowed it access to the server.
However, it is believed that the threat actor did not compromise the actual DatPiff website but rather a server with old database backups.
What should DatPiff users do?
Although this database is very old, if someone has an account on the DatPiff platform, it is a good idea to reset their password and use a new, unique and strong password.
See also: Malicious Telegram installer installs Purple Fox malware on infected machines
Those who use the same password on other sites should change it there as well so that their other accounts are not compromised.
DatPiff members can search their email addresses on Have I Been Pwned, to see if they are among the 7 million users affected by this data breach.
Source: Bleeping Computer
