124 Million Passwords Stolen: Yours Is Probably in There Too
The good news: you can check whether yours has made the cut.
The breach notification service Have I Been Pwned has added 124 million unique passwords and 56.3 million email addresses to its database, the result of what security researchers diplomatically call stealer logs. You can think of those as the very thorough diary entries that infostealer malware keeps while living rent-free on your PC.
The data originates not from a single dramatic hack of one big company, the kind where a CEO gets to send a deeply apologetic email promising we take your security very seriously. No, this time the credentials were lifted directly off hundreds of millions of infected end-user devices, one browser-saved password at a time. Silent, patient, and utterly indifferent to your feelings.
You can check whether your email address or passwords appear in the June 2026 stealer log dataset directly at haveibeenpwned.com. Checking is free and takes about ten seconds. Less time than it will take to recover a hijacked account.
How Infostealers Work (Or: How Your Browser Betrayed You)
Infostealer malware is exactly what it sounds like: software that sneaks onto a Windows PC and systematically harvests everything your browser helpfully remembered for you. Passwords, cookies, session tokens, autofill data, the full buffet. The malware then packages it all into tidy "stealer logs" and sends them off to whoever paid for the service.
The particularly charming detail is that many victims never notice. The malware doesn't encrypt your files or demand Bitcoin. It just watches, copies, and leaves. You carry on entering "the same password you use for everything" into websites, blissfully unaware that someone in another timezone is already logged into your accounts.
Have I Been Pwned does not disclose which specific malware families contributed to this particular dataset, only that the corpus spans hundreds of millions of stealer log records. The 124 million unique passwords extracted from those records have now been added to HIBP's Pwned Passwords database, where you can check whether yours has made the cut.
"But I Use a Strong Password"
Good for you. Is it the same strong password you use on twelve other sites? Because that's what credential stuffing attacks were invented for. Criminals take a leaked username-and-password pair and try it on every major service they can think of, betting — correctly, in most cases — that people reuse passwords. It's a numbers game, and with 124 million entries to work with, the numbers are favorable to exactly the wrong people.
What to Actually Do Right Now
1. Check your email at haveibeenpwned.com. If it shows up, assume the associated passwords are compromised and change them immediately, not just on the site you think was affected, but everywhere you used that same password.
2. Enable two-factor authentication (2FA) wherever possible. A stolen password is annoying; a stolen password combined with 2FA is a dead end for the attacker. Most major services — email, banking, social networks — support it.
3. Use a password manager. This is the advice that everyone gives and approximately nobody follows until after something goes wrong. A password manager generates a long, unique, random password for every site and remembers it so you don't have to. You only need to remember one master password. That's it. The era of "Fluffy1984!" as a security strategy is over.
Popular options freely available on UpdateStar include:
-
Bitwarden — open-source, free, cross-platform, and just updated to version 2026.6 with new device management features. Arguably the best free option available today.
-
KeePass — the classic offline option, keeping your password vault local and under your own control.
-
1Password — a polished, subscription-based option with strong family and team sharing features.
The Bigger Picture
This incident is a useful reminder that data breaches are no longer just a corporate problem. Infostealers democratize the process: your computer is the breach, and the target is you personally, not some faceless database server in a data center.
The lesson, as always: unique passwords per site, 2FA where available, and a password manager to tie it all together. These three steps won't make you immune to malware — keep your antivirus updated and be selective about what you download, but they will ensure that a compromised password on one site doesn't cascade into a compromised life.