Particle.news
Download on the App Store

Have I Been Pwned Adds Record Cache of Nearly 2 Billion Emails and 1.3 Billion Passwords

Compiled by Synthient from older leaks, the trove heightens credential‑stuffing risk, prompting urgent user remediation.

Overview

  • Troy Hunt indexed the dataset into Have I Been Pwned after spot‑checking with affected users, confirming many passwords are real and in active use.
  • About 625 million passwords were previously unseen by HIBP, pushing its database beyond roughly 17 billion exposed accounts.
  • The collection aggregates credentials from years of prior breaches and credential‑stuffing lists rather than a new hack of a major provider.
  • People can check exposure by searching emails on haveibeenpwned.com and by using the Pwned Passwords tool without revealing their actual passwords.
  • Security guidance urges changing compromised and reused passwords, enabling two‑factor authentication, using password managers, and moving to passkeys where available.