A breach at the parody social site Myspace93, part of the Windows93 project, exposed data from roughly 46,000 accounts, including plaintext passwords, usernames, email addresses, and IP addresses. According to breach details later cataloged by Have I Been Pwned, the intrusion originated in January 2021 when attackers abused access to a beta application to download server files, and the stolen data was subsequently leaked in June.
Reporting on the incident said trusted members of a Windows93 Discord community had been granted beta access and then used it to obtain an unencrypted credential store, while also sharing a download tool and instructions in chat and distributing additional stolen files across other platforms. After the compromise became public, Myspace93 stopped new account registrations, and co-creator Janken said social network-related services across Windows93 offshoots were shut down.

See attribution, scope, and your downstream exposure.
5 events from the most recent confirmed update back to the earliest known activity.
On 2026-05-21, Have I Been Pwned published the Windows93/Myspace93 breach entry after ingesting the dataset. The listing documented roughly 46,000 exposed accounts with plaintext passwords and related personal data.
On 2021-07-04, co-creator Janken published a note explaining that trusted Windows93 Discord members abused beta access to steal server files and credentials. He also said Myspace93 stopped new account registrations and that related social-network services across Windows93 offshoots were shut down in response.
In June 2021, the operator discovered attackers were actively abusing leaked credentials, including using the Myspace admin password to inject XSS payloads into the site. The incident prompted emergency patching and a mandatory password reset for accounts created before February 2021.
In June 2021, the compromised Myspace93 data was leaked, making the exposed account information publicly available. Reports indicate the attackers also shared tools and instructions related to downloading the files.
In January 2021, attackers used access to a beta application on the Windows93/Myspace93 parody site to download server files and obtain an unencrypted store of Myspace93 credentials. The breach affected about 46,000 accounts and exposed usernames, email addresses, IP addresses, and plaintext passwords.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See attribution, scope, and whether this vendor sits anywhere in your supply chain.
3 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.