Billions of passwords: HaveIBeenPwned receives its biggest data update ever

Here we go your daily reminder that the internet is basically a leaky bucket.

HaveIBeenPwned (HIBP), Troy Hunt’s "hey, were you owned today"? service, just inhaled its biggest data dump ever: 1,957,476,021 fresh, unique email addresses. Yes, unique - someone already did the deduping so you don't have to. Toss in 1.3 billion passwords (with 625 million brand-new to HIBP), and you have got enough credentials to keep every bored botnet busy until the sun burns out.

Where'd it all come from? From credential-stuffing lists compiled by Synthient - the greatest hits of past breaches, lovingly aggregated so attackers can try your one favorite password on every site you’ve ever used. Because of course people still recycle passwords like it's 2009.

Why this is bad (and somehow still news)

If one site spills your login, crooks try it everywhere else. Reused password? Congrats, they just unlocked your other accounts like a skeleton key from the discount bin.

How not to be low-hanging fruit

Use unique, complex passwords per site (a password manager exists for exactly this).

Turn on 2FA so a leaked password isn’t a golden ticket.

Or skip passwords entirely and use passkeys like it’s the current decade.

"But is the data real?"

Hunt sanity-checked it: he pinged random HIBP subscribers and asked if the credentials looked familiar. The answers: "Yep". Some were antiques, some were alarmingly current. Fun times.

Go look up your digital mess

Head to HIBP and:

  • Enter your email to see which breaches you are in and what else got spilled (usernames, DoB, IP addresses, the usual oversharing).

  • Use the password checker to see how many times a string has appeared out in the wild.

  • And no, HIBP won't connect your email and password for you - because mixing those is how you get a sequel to this story.

In short: your logins are probably in there. Act accordingly.

about author