---
title: "Massive Release of Breached Passwords Likely Includes Yours"
description: "A gigantic trove of passwords has been released by bad actors, and there's a very good chance that yours is on there."
date: "2024-01-18"
modified: "2024-01-18"
authors:
  - name: "Noor Al-Sibai"
    job_title: "Senior Staff Writer"
    link: "https://futurism.com/authors/nooralsibai"
url: "https://futurism.com/the-byte/giant-password-data-breach"
categories:
  - "Future Society"
tags:
  - "data breach"
  - "hackers"
  - "passwords"
  - "the digest"
---

# Massive Release of Breached Passwords Likely Includes Yours

![A gigantic trove of passwords has been released by bad actors, and there's a very good chance that yours is on there.](<https://futurism.com/wp-content/uploads/2024/01/giant-password-data-breach.jpg>)
*\<em\>Image: Getty / Futurism\</em\>*

## Don't Pass Go

A gigantic trove of passwords has been released by bad actors, and there's a very good chance that yours is on there.

According [to Troy Hunt](<https://www.troyhunt.com/inside-the-massive-naz-api-credential-stuffing-list/>), the man behind the excellent breach notification site "[Have I Been Pwned](<https://haveibeenpwned.com/>)" — which allows users to look up your email and see if and where your passwords and other user information have been compromised — it's one of the largest collections of breached data he's ever seen appear online.

To a data defender like Hunt, "large" is not an understatement. The cache of files, dubbed "Naz.API," contains more than 71 million email addresses and 100 million passwords. Thus far, more than 400,000 Have I Been Pwned (HIBP) subscribers have been impacted.

https://twitter.com/haveibeenpwned/status/1747621747073970679

It's not all fresh. The researcher said in his blog post that more than 65 percent of the email addresses in the breach had already been seen before in other HIBP datasets. This suggests, Hunt explained, that although a majority of the stolen data has already been floating around, over a third of it appears to be newly harvested.

"When a third of the email addresses have never been seen before, that's statistically significant," he wrote. "This isn't just the usual collection of repurposed lists wrapped up with a brand-new bow on it and passed off as the next big thing; it's a significant volume of new data."

## Logged On

As Hunt explains, much of the data is from what's known as "stealer logs," or malware installed on someone's device that captures their login info. In the case of Naz.API, these lists were believed to have been gleaned from illicit.services, a now-defunct site that easily allowed bad actors to search for data based on someone's name or email address.

When trawling through the compromised data for his own, Hunt discovered a password he'd used before the year 2011, which seems to indicate that some of the info is very old indeed.

https://twitter.com/troyhunt/status/1747250819605381276

Perhaps the biggest takeaway, especially considering the more than decade-old password of his own that Hunt found in the dataset, is that reusing passwords across years and sites is a very insecure data practice. Citing the recent [23andme breach](<https://www.wired.com/story/23andme-credential-stuffing-data-stolen/>), the researcher pointed out that as long as "password reuse remain\[s\] rampant," so too will fallout from these kinds of hacks.

His advice?

"Definitely get out in front of this one as early as you can" by replacing your recycled credentials with a [password manager](<https://www.vice.com/en/article/59yv5x/how-password-managers-work-and-why-you-should-use-one>).

**More on massive hacks:** [*Oops! 23andMe Admits Hackers Stole 7 Million Customers' Genetic Data*](<https://futurism.com/neoscope/23andme-hackers-genetic-data>)

## Author
At Futurism, I've often been drawn to unpacking the narratives that underlie technological, scientific and medical progress, with a special interest in areas of conflict and ambiguity that end up setting agendas and steering the fates of both elites and the hoi polloi. I'm a committed generalist, but I often find myself returning to work involving NASA and the private space sector, the effects of AI on media and society, and the mechanics of the pharmaceutical industry, with a specific focus on the spread of GLP-1 drugs like Ozempic and Wegovy. Prior to Futurism, I worked for publications ranging from Media Matters and Truthdig to Raw Story and Bustle. I'm also the author of "Myspace Scene Queens," a 2024 title in Instar Books' acclaimed "Remember the Internet" series. My work at Futurism has been cited by outlets including the New Yorker, Slate, Nieman Lab, the Verge, the MIT Technology Review, the Sunday Times, and the Daily Beast. I grew up in North Carolina, attended the University of North Carolina at Asheville, and now live in Brooklyn, New York. In my free time, I'm an avid reader and music fan; you can probably find me at a local poetry reading, concert, underground rave, or DJ set. I'm the proud parent of an ineffable orange cat named Mee-Mow.

### Author social links  
[Bluesky](<https://bsky.app/profile/noorfromfuturism.bsky.social>)