Raaga Breach: 10.2M Accounts — Passwords Exposed
In December 2025, data allegedly breached from the Indian streaming music service 'Raaga' was posted for sale to a popular hacking forum . The data contained 10M unique email addresses along with names, genders, ages (in some cases, full date of birth), postcodes and passwords stored as unsalted MD5...
Overview
In December 2025, a significant data breach impacted the popular Indian music streaming service, Raaga. A dataset containing the personal information of over 10 million users was stolen and subsequently offered for sale on a prominent hacking forum. The exposure of sensitive personal details, combined with weakly protected passwords, makes this a critical security incident for anyone who has ever used the service.
What Was Exposed
The stolen data is extensive and includes several key pieces of personal information for each affected account. The confirmed exposed data includes:
- Email Addresses: The primary contact and login identifier.
- Names and Genders: Basic personal identification details.
- Passwords: These were stored using an outdated and weak method known as an unsalted MD5 hash. This is akin to locking a door with a basic, easily picked lock, making it relatively simple for criminals to convert these hashes back into the original plaintext passwords.
- Additional Personal Data: For many users, the breach also included ages, full dates of birth, and postcodes. This combination of information is particularly sensitive.
Potential Impact
The exposure of this data creates multiple serious risks for victims. The primary danger is account takeover. Since many people reuse passwords across multiple websites, criminals can use the cracked Raaga passwords to attempt to log into your email, social media, banking, or shopping accounts. This is the most immediate threat.
Secondly, the combination of your name, date of birth, email, and postcode provides a powerful toolkit for targeted phishing attacks. Scammers can craft highly convincing emails pretending to be from banks, government agencies, or other trusted entities, using your real details to gain your trust. This information can also be used for identity fraud or sold to other cybercriminals on the dark web.
Recommendations
If you have ever had a Raaga account, you must take immediate action to protect yourself.
- Change Your Raaga Password Immediately: Log into your Raaga account and update your password to a new, strong, and unique one. Do not reuse a password from any other service.
- Change Passwords on Other Accounts: If you used the same or a similar password for Raaga on any other website (especially email, social media, or financial accounts), change those passwords immediately as well.
- Enable Two-Factor Authentication (2FA): Wherever possible, especially on your primary email account, enable 2FA. This adds a critical second layer of security, like a code sent to your phone, that stops hackers even if they have your password.
- Be Vigilant Against Phishing: Be extremely cautious of unsolicited emails, texts, or calls asking for personal information or directing you to click on links. Verify the sender’s authenticity independently before responding.
- Monitor Financial Statements: Keep a close eye on your bank and credit card statements for any unauthorized transactions.
How to Check If You’re Affected
The breach has been verified and documented by the reputable service “Have I Been Pwned.” You can easily check if your email address was involved in this or any other known breach.
- Visit haveibeenpwned.com.
- Enter your primary email address(es) into the search bar.
- The site will show you if your data was found in the Raaga breach. You can view the specific details of this incident here: https://haveibeenpwned.com/Breach/Raaga.
Taking these steps promptly is the best way to secure your accounts and personal information following this breach.
Investigate Breaches Safely with NordVPN
Researching exposed data, paste sites, or threat actor infrastructure? Route your OSINT traffic through a VPN to avoid attribution and keep your investigation IP separate from your corporate network.
Get NordVPN for ResearchAffiliate link — we may earn a commission at no extra cost to you.
Never miss a data breach report
Get real-time security alerts delivered to your preferred platform.
Related Breach Reports
In April 2026, education company McGraw Hill confirmed a data breach following an extortion attempt . Attributed to a Salesforce misconfiguration, the company stated the incident exposed "a limited set of data from a webpage hosted by Salesforce on its platform". More than 100GB of data was later pu...
In April 2026, the music trivia platform SongTrivia2 suffered a data breach that was subsequently published to a public hacking forum . The data contained a total of 291k unique email addresses sourced from either Google OAuth logins or accounts created on the site, the latter also containing bcrypt...
In March 2026, the personal development and achievement media brand SUCCESS suffered a data breach . The incident exposed 250k unique email addresses along with names, IP addresses, phone numbers and, for a limited number of staff members, bcrypt password hashes. The data also included orders contai...
In March 2026, a breach of one of the many iterations of the BreachForums hacking forum known as "Version 5" was publicly disclosed . The incident exposed 340k unique email addresses along with usernames and argon2 password hashes.