One of the biggest password dumps in recent history has been revealed - but there's an easy way to find out if you're at risk

Representational image depecting cybersecurity protection
(Image credit: Shutterstock)

For roughly four months, a gigantic email and password dump was circulating on the dark web, and no one in the cybersecurity community noticed, until now.

Have I Been Pwned? (HIBP) has added a new database containing roughly 71 million email addresses to its platform. The service allows users to see if their email addresses were picked up by threat actors at any time in the past and, if so, which service was breached to obtain the information.

While announcing the new addition, HIBP owner Troy Hunt says he dismissed the database earlier because it seemed to be nothing more than old information - repackaged. Upon closer inspection, however, he determined that a third of the email addresses were brand new, making the data dump “statistically significant”.

Significant data volume

This isn't just the usual collection of repurposed lists wrapped up with a brand-new bow on it and passed off as the next big thing; it's a significant volume of new data,” Hunt wrote. “When you look at the above forum post the data accompanied, the reason why becomes clear: it's from ‘stealer logs’ or in other words, malware that has grabbed credentials from compromised machines.”

When a user types in their email in the Have I Been Pwned? service, if their email pops up under the “Naz.API” submission, that means that they were, most likely, infected by malware at some point in the past (or are infected still). That also means that the malware stole passwords for various services. Unfortunately, it’s difficult to determine which service (unless the user recognizes the unique username/password combination). Some of the services mentioned include Facebook, Yahoo, Roblox, eBay, and others. 

The database counts 319 files, totaling 104GB. Exactly 70,840,771 unique email addresses were exposed, and 427,308 individual Have I Been Pwned? subscribers impacted.

More from TechRadar Pro

TOPICS

Sead is a seasoned freelance journalist based in Sarajevo, Bosnia and Herzegovina. He writes about IT (cloud, IoT, 5G, VPN) and cybersecurity (ransomware, data breaches, laws and regulations). In his career, spanning more than a decade, he’s written for numerous media outlets, including Al Jazeera Balkans. He’s also held several modules on content writing for Represent Communications.

Read more
Cartoon Phishing
One of the largest data leaks ever sees info on 1.5 billion people leaked online
Data leak
Top collectibles site leaks personal data of nearly a million users
A man looking at a tablet with a brown Best Buy package on the desk in front of him
Huge Christmas data breach - 14 million shipping records leaked, putting shoppers at risk
Cartoon Phishing
Over a billion credentials stolen were stolen in malware attacks in 2024
Security padlock and circuit board to protect data
Foh&Boh data leak leaves millions of CVs exposed - KFS, Taco Bell, Nordstrom applicants at risk
No broadband network
Massive online data breach sees 2.7 billion records leaked - here's what we know
Latest in Security
A stylized depiction of a padlocked WiFi symbol sitting in the centre of an interlocking vault.
Broadcom warns of worrying security flaws affecting VMware tools
URL phishing
HaveIBeenPwned owner suffers phishing attack that stole his Mailchimp mailing list
Ransomware
Cl0p resurgence drives ransomware attacks to new highs in 2025
Google Chrome
Google Chrome security flaw could have let hackers spy on all your online habits
cybersecurity
Chinese government hackers allegedly spent years undetected in foreign phone networks
Data leak
A major Keenetic router data leak could put a million households at risk
Latest in News
inZOI promotional material.
inZOI has become the most wishlisted game on Steam, but I wouldn't get too caught up in the hype
Xbox Series X and Xbox wireless controller set to a green background
Xbox Insiders are currently testing a new Game Hub feature that looks useful, but I've got mixed feelings about it
A stylized depiction of a padlocked WiFi symbol sitting in the centre of an interlocking vault.
Broadcom warns of worrying security flaws affecting VMware tools
Microsoft Surface Laptop and Surface Pro devices on a table.
Hate Windows 11’s search? Microsoft is fixing it with AI, and that almost makes me want to buy a Copilot+ PC
Oura Ring 4
Activity tracking on Oura Ring is about to get a whole lot better, but I've got bad news about your step count
Google Pixel Buds Pro 2
Cleaned your Pixel Buds Pro 2 recently? If not, you might be getting worse sound