Earbits reported an account-information exposure in January 2016. The company said it found no evidence that data was accessed, that passwords were encrypted, and that it did not store payment-card or other sensitive information. Those are Earbits’ statements, not an independent forensic certification. If you reused your Earbits password on another service, change it there.
Was Earbits hacked?
In January 2016, Earbits reported a security breach or exposure involving account information. BetaNews reported on January 20 that usernames and passwords were exposed. Separately, TechNewsWorld’s breach diary reported that security researcher Chris Vickery found a database containing private account information online.
The accounts were not necessarily proven to have been accessed or misused. The reviewed reports do not establish how long the information was exposed or provide a complete inventory of the database fields.
How many Earbits users were affected?
TechNewsWorld attributed the figure of about 325,000 user accounts to researcher Chris Vickery. This is the widely cited scale of the reported exposure; the available reports do not establish that all of those accounts were accessed.
Quick wins for a faster PC:
Scan for outdated or missing drivers - takes under a minuteDriver Scan →Repair Windows errors before they cause bigger problemsFix Now →#1 Best Overall
Did the breach expose passwords, credit cards, or music files?
Earbits founder Joey Flores said passwords were encrypted and that the company had confirmed no data was accessed during the vulnerable period. He also said no music files or other media were taken, and that Earbits did not store credit-card or other sensitive information. BetaNews published Flores’ statement in January 2016.
That reassurance should be understood as the company’s assessment. The reviewed reporting does not provide an independent forensic finding confirming that no one accessed the exposed information. It does not report theft of music files or payment-card records.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Do you need to change your Earbits password?
If you still use the same password on another service, change it there. The reported exposure involved usernames and passwords, and password reuse could put another account at risk even if Earbits’ own assessment was correct.
Quick Recap
Best Value
- Password reused elsewhere: Change it on every other site where you used it, and use a distinct password for each account.
- Password still active on an Earbits account: If you can access the account, change it. Flores said users could change their password at Earbits.com.
- Unique, no-longer-used password: The reports do not establish that you must take further action, but you can change it if you still have access and prefer to do so.
- Exposure notification: The reviewed reports do not identify an authoritative individual notification or account-checking service. Do not assume a message claiming to confirm exposure is genuine without verifying its source.
Sources and what they establish
- BetaNews, January 20, 2016 reported Earbits’ breach statement and the company’s claims about encryption, access, and stored payment information.
- TechNewsWorld, January 2016 reported the exposure of a database and attributed the estimate of about 325,000 accounts to Chris Vickery.
- The reviewed reports do not independently establish access or use of the information, the duration of exposure, or a complete list of exposed fields.
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

