Hack brief: Astonishing 773 mln records exposed in monster breach – media

16:40, 18 January 2019
World
706 0
Flickr Free Images

There are breaches, and there are megabreaches, and there's Equifax. But a newly revealed trove of leaked data tops them all for sheer volume: 772,904,991 unique email addresses, over 21 million unique passwords, all recently posted to a hacking forum.

The data set was first reported by security researcher Troy Hunt, who maintains Have I Been Pwned, a way to search whether your own email or password has been compromised by a breach at any point. (Trick question: It has.) The so-called Collection #1 is the largest breach in Hunt's menagerie, and it's not particularly close, according to WIRED.

If anything, the above numbers belie the real volume of the breach, as they reflect Hunt's effort to clean up the data set to account for duplicates and to strip out unusable bits. In raw form, it comprises 2.7 billion rows of email addresses and passwords, including over a billion unique combinations of email addresses and passwords.

Read alsoHundreds of German politicians hacked, excluding those from far-right AfD – media

The trove appeared briefly on MEGA, the cloud service, and persisted on what Hunt refers to as "a popular hacking forum." It sat in a folder called Collection #1, which contained over 12,000 files that weigh in at over 87 gigabytes. While it's difficult to confirm exactly where all that info came from, it appears to be something of a breach of breaches; that is to say, it claims to aggregate over 2,000 leaked databases that contain passwords whose protective hashing has been cracked.

"It just looks like a completely random collection of sites purely to maximize the number of credentials available to hackers," Hunt tells WIRED. "There's no obvious patterns, just maximum exposure."

If you see a spelling error on our site, select it and press Ctrl+Enter