Troy Hunt is at it again, 773 million email data breach

HoNeYBiRD

Elite Member
Joined
May 1, 2009
Messages
10,187
Reaction score
12,580
He added almost 773 million email addresses and over 21 million passwords to his HIBP database. This data was circulating on a hacking forum and was uploaded to Mega, total of 87 GB. :eek: This breach is a set of email addresses and passwords totalling 2,692,818,238 rows. It's made up of many different individual data breaches from literally thousands of different sources. In total, there are 1,160,253,228 unique combinations of email addresses and passwords. The unique email addresses totalled 772,904,991. There are 21,222,975 unique passwords. Some of these were already known/breached and existed in Troy's database, but 140 million email addresses and 10 million passwords didn't, these are new additions to his database. The list of (allegedly) breached sites: https://pastebin.com/UsxU4gXA

I guess everyone knows this by now, but if not, check here if you have been compromised: https://haveibeenpwned.com
I wasn't aware of this until now, but apart from the email addresses you can check individual passwords too here: https://haveibeenpwned.com/Passwords. This can come in handy, if you worry about particular accounts.
Get notified, when you get breached: https://haveibeenpwned.com/NotifyMe (It can be too late though, because obviously it only notifies you of the breach, when it gets uploaded into the database, which can happen a lot later than the actual breach happened.)

Source: https://www.troyhunt.com/the-773-million-record-collection-1-data-reach/
 
Last edited:
shit, one of my old email shows as pawned.. crap.. what should I do?
Edit: I don't use that email anywhere anymore.. im guessing it is no big deal, right.. :anyway:
 
Last edited by a moderator:
Data breach was from a few years back.
 
What if this website to check pwned emails collects all of them
A possibility. But the site is around since 2013 and the guy behind it seems legit to me. What would he do with email addresses without belonging data? He already have billions of email addresses. :)

Data breach was from a few years back.
Well, it might not be fresh. It came from a lot of sources, 12k files. 140 million email addresses and 10 million passwords were a new addition to his database, so those weren't (widely) available before this breach. And even if it's a few years old, it can still contain more than enough working combos. People don't usually change their passwords, unless they required to do so.
 
All the emails I ever owned have been pwned at some point.

Have to use MFA on everything now as well as keeping passwords that return zero results on troys site.
 
I have the old one aka. the 1.4 billion pw leak (approx 42GB) this one includes the whole older one + some new shit. #doghacker
 
We use 256-bit encryption, you are 100% secure.
 
If we check our mail , that means him will registred our mails too :) nice trick too get more emails :)))
 
All the emails I ever owned have been pwned at some point.

Have to use MFA on everything now as well as keeping passwords that return zero results on troys site.
Yes, 2FA/MFA has saved my ass on multiple occasions. My Gmail account wasn't hacked thanks to only that. After checking his password database, i needed to retire two of my weaker passwords i use on not too important places. Most of my emails are in the database too, no biggy, with just email addresses they can't do much.
 
Phew, just checked. Nothing in there...lucky me. 2FA kinda annoying but seems like I need to enable it everywhere to be safe
 
I own a 12GB email/password list from October 2018, I would do something with the emails but I have no idea what (Minecraft related)
 
Seems like a fucking ad campaign to 1password.
Yea, you can look at it that way. I don't use password managers, so i skipped that part entirely. I guess he needs to live off of something just like all of us. Running a site like that must cost some money too, it receives around 100k visitors per day. I don't think that you can really blame him for not running the whole show from his own pocket. Now that you mentioned it, i checked up on it: he partnered with them in March, he made a long-ass post about it on his blog. It must be a nice sum, but at least haveibeenpwned is free (according to the mentioned blogpost he wants to keep it that way) and you don't have to fight with annoying pop-ups either. If this would be the only type of advertising, the net would be a much cleaner and nicer experience for everyone, especially the technically inclined, who have never heard about adblockers. But that's a different story.
 
Back
Top