Qobuz data breach?

I have just had an email from NordVPN dark web monitoring. Checking their web site I found one of my logins had been found on the dark web …

A large collection of email addresses and passwords was found online. Your email address and one or more passwords were exposed. It’s not possible to confirm where each record originally came from, and some entries may be old, duplicated, or linked to known websites, while others can’t be tied to specific services.

The login details were my Qobuz login. Naturally, I have now changed my password.

I would advise Qobuz subscribers to do the same.

[edit]

The breach could have occurred anywhere the login is stored, such as bubbleUPnP, which is what I mainly use to stream Qobuz. Although thinking about it I would expect the app to store it locally, not in the cloud. But what do I know?

[edit]

re-reading the web site I saw this

We’ve expanded Dark Web Monitor™ to scan large collections of leaked credentials, helping you spot exposed passwords and potentially compromised accounts.These collections combine data from stealer logs and past breaches. As a result, you may see additional alerts about previously undetected exposures, some dating back years.

Show less

2 Likes

Nord has not notified me of a leak of my Qobuz login details, so it might not be Qobuz where the problem is.

1 Like

Thanks guys,

I have also found that MacOS support for Rosetta that allows Intel based apps to run on Apple Silicon is ending soon. So, I reinstalled the Qobuz app on my MAC which is Apple Silicon,picking the Apple Silicon option.

BubbleUpnp was breached some time ago so this the likely source.

1 Like

NordVPN hasn’t sent me a message and I use quboz so I suspect it may be a breach elsewhere, maybe

1 Like