I have just had an email from NordVPN dark web monitoring. Checking their web site I found one of my logins had been found on the dark web …
A large collection of email addresses and passwords was found online. Your email address and one or more passwords were exposed. It’s not possible to confirm where each record originally came from, and some entries may be old, duplicated, or linked to known websites, while others can’t be tied to specific services.
The login details were my Qobuz login. Naturally, I have now changed my password.
I would advise Qobuz subscribers to do the same.
[edit]
The breach could have occurred anywhere the login is stored, such as bubbleUPnP, which is what I mainly use to stream Qobuz. Although thinking about it I would expect the app to store it locally, not in the cloud. But what do I know?
[edit]
re-reading the web site I saw this
We’ve expanded Dark Web Monitor™ to scan large collections of leaked credentials, helping you spot exposed passwords and potentially compromised accounts.These collections combine data from stealer logs and past breaches. As a result, you may see additional alerts about previously undetected exposures, some dating back years.
Show less