Many people will land on this page after learning that their email address has appeared in a data breach. A collection is a set of email addresses and passwords totaling 2,692,818,238 rows. It's made up of many different individual data breaches from literally thousands of different sources.
In total, there are 1,160,253,228 unique combinations of email addresses and passwords. This is when treating the password is case sensitive but the email address as not case sensitive. This also includes some junk because hackers being hackers, they don't always neatly format their data dumps into an easily consumable fashion.
The unique email addresses totaled 772,904,991. This is the headline you're seeing as this is the volume of data that has now been loaded into Have I Been Pwned (HIBP). It's after as much clean-up as I could reasonably do and per the previous paragraph, the source data was presented in a variety of different formats and levels of "cleanliness". This number makes it the single largest breach ever to be loaded into HIBP.
There are 21,222,975 unique passwords. As with the email addresses, this was after implementing a bunch of rules to do as much clean-up as I could including stripping out passwords that were still in hashed form, ignoring strings that contained control characters and those that were obviously fragments of SQL statements.
That's the numbers, let's move onto where the data has actually come from.
Data Origins
Last week, multiple people reached out and directed me to a large collection of files on the popular cloud service, MEGA (the data has since been removed from the service). The collection totaled over 12,000 separate files and more than 87GB of data. One of Troy Hunt's https://www.troyhunt.com/about/ contacts pointed him to a popular hacking forum where the data was being socialized.
Who is behind Have I Been Pwned (HIBP)
His name is Troy Hunt, a Microsoft Regional Director and Most Valuable Professional awardee for Developer Security, blogger at troyhunt.com, international speaker on web security and the author of many top-rating security courses for web developers on Pluralsight.
Password reuse and credential stuffing.
Password reuse is normal. It's extremely risky, but it's so common because it's easy and people aren't aware of the potential impact. Attacks such as credential stuffing take advantage of reused credentials by automating login attempts against systems using known emails and password pairs.
Password hacking compromised more than 150 million accounts this past year. (https://breachalarm.com/)
We comb the depths of the Internet to find stolen password lists that have been hacked, leaked or compromised, and we spot the email addresses of the users those passwords belong to. We keep a database of those email addresses so that you can check easily whether your email address and password have been included in any of these breaches.
The world is leaking passwords
As you read this, more and more passwords are being stolen and leaked in data breaches.
Get a password manager!
You have too many passwords to remember, you know they're not meant to be predictable and you also know they're not meant to be reused across different services. If you're in this breach and not already using a dedicated password manager, the best thing you can do right now is go out and get one. A password manager provides you with a secure vault for all your secrets to be stored in (not just passwords, I store things like credit card and banking info in mine too), and its sole purpose is to focus on keeping them safe and secure. The safety protocols that are used to store passwords are amazing.
There are many passwords manager. https://1password.com/, https://www.lastpass.com/
But I only use LastPass. From the first use in 2010, I am still using it up to date. And I am recommending anyone to get a better password, harder to hack, never forget a password and impossible to hack in data storage of passwords (for now ->2019). It generates any password you need of enormous length, characters, numbers and the best thing it saves it automatically.
The company developed The Last Pass in 2008. The year it all started in Virginia with four security-minded friends. From there it just gets better.
Strong encryption algorithms.
We’ve implemented AES-256 bit encryption with PBKDF2 SHA-256 and salted hashes to ensure complete security in the cloud. You’ll create an account with an email address and a strong master password to locally-generate a unique encryption key.
Local-only encryption.
Your data is encrypted and decrypted at the device level. Data stored in your vault is kept secret, even from LastPass. Your master password and the keys used to encrypt and decrypt data are never sent to LastPass’ servers and are never accessible by LastPass.
A password manager is also a rare exception to the rule that adding security means making your life harder. For example, logging on to a mobile app, web page, the game is dead easy.
You can also add another security layer for war against hackers. Chrome add-on HackNotice. It also exists for Android and IOS. It notifies a user that there were digital identity leaks, which may include sensitive information, such as usernames, passwords, and other risk-related information. It also informs you if the web page was recently hacked.
Another great app who is patrolling the changes of system settings, files also prevent hackers from modifying our system is called WinPatrol. https://www.winpatrol.com/
The most effective AntiRansom product on the market.
Protect your personal computers from Ransomware, Malware, Zero-Day Threats and more with WinPatrol WAR. WinPatrol WAR uses our powerful Artificial Intelligence engine to give ransomware and malware a dose of their own medicine and block them before they can infect. The program really has Spartans look. It's function operate on a passive level. If everything is O.K. you wouldn't notice running of the program.
The most basic version, which serves its purpose, are completely free.