MySpace Nukes Massive Security Loophole (But Go Delete Your Stuff Anyways)

Remember Myspace? Yeah, it’s still a thing. And for months, the social network reportedly had a security flaw that made it ridiculously easy to hack into any profile with just a date of birth.


Security researcher Leigh-Anne Galloway first reported the flaw on her blog Monday morning. She said she’s been trying to get Myspace to fix it since April, but hasn’t heard back from anyone.

Galloway says the flaw resided within Myspace’s account recovery page. When a user tried to recover their account, they were asked to enter their full name, email, and date of birth. And apparently any account could be hijacked by just inputing the person’s birthday, Galloway says, because Myspace wasn’t validating users’ emails. After that, Myspace would just log you into the account and let you change the password and associated email.

But if you’re interested in testing the security flaw (or stealing someone’s account), hear this: As Galloway’s post was picked up by numerous news organizations, Myspace pulled the recovery page that Galloway cites in her post ( We’re not sure when, exactly, Myspace made the change, but that URL now redirects to a “Log in” support page. The original form is still viewable via the Internet Archive’s Wayback Machine.

Another thing you should know about recovering old Myspace profiles is that there’s hardly any information left. When Myspace redesigned its site and rebranded as a music-focused social network, it changed everyone’s profiles to plain black and white, empty pallets.

The only things you might be able to recover are some old profile photos, videos, and music playlists, but your coded wallpaper, glittery GIFs from Photobucket, and your Top 5 are all gone. Regardless, you should probably try to recover your own account before someone else does and steals the three remaining pre-teen-era public photos of you.

This is not the first time Myspace’s security has been compromised. Last year, about 360 million account passwords were leaked. LeakedSource reported that it was considered one of the biggest data breaches in history.


“It seems Myspace wants us all to take security into our own hands,” Galloway wrote on her blog. “If there is a possibility that you still have account on Myspace, I recommend you delete your account immediately.”

We’ve reached out to Myspace, and we’ll update this story if we hear back.

[ Leigh-Anne Galloway via The Verge]




What happens if we have an old account on there that we don’t know the password to and the email and backup email address no longer exists? lol. I mean, my account on there was made in the mid-2000's and yeah.