Data breach
Collection #1-5
- Records
- 2,788,586,065
- Breach date
- 7 January 2019Estimated
- Added
- 1 December 2024
What was exposed
2 types of data · 1 puts you at serious risk
- Email addresses2,788,586,065
- Passwords2,633,647,822
About this breach
In January 2019, a colossal set of hacked credentials known as Collection #1-5 began circulating among cybercriminals. The listing contains 2,788,586,065 rows of data, including roughly 2.79 billion email addresses and about 2.63 billion passwords. This is not a breach of a single company. It is a compilation, assembled from thousands of earlier breaches and dumps, and it was never claimed by any hacking group in our records. Researchers who examined parts of the series found material drawn from well-known incidents such as the Yahoo, LinkedIn, and Dropbox breaches, mixed with countless smaller leaks, some years old.
Breach Timeline
January 17, 2019: Security experts revealed details of Collection #1, the first installment of the series, a set of files containing usernames and passwords tied to hundreds of millions of unique email addresses, according to Wired.
February 1, 2019: Sophos reported that researchers at Germany's Hasso-Plattner Institute had analyzed Collections #2 through #5, estimating about 2.2 billion unique email and password pairs across roughly 845 GB of data and 25 billion records.
What Information Was Compromised?
Our analysis found the following data types in this breach: email addresses (2,788,586,065) and passwords (2,633,647,822). The password count is lower than the row count, which means some entries in the compilation lack a password.
Because this is an aggregated collection rather than a single incident, there is no one company notice describing additional fields, and we have not verified any further data types beyond those above.
Not every individual is affected by every type of data listed here.
What Are the Potential Risks for Affected Individuals?
The main danger from a credential compilation is credential stuffing. Attackers take email and password pairs from the list and automatically try them on banks, email providers, shopping sites, and social networks. If you reused the same password on multiple accounts, a single reused password could open many of them.
Other risks follow from that exposure:
Account takeover. Anyone whose email and password pair appears in the compilation may find attackers logging into accounts that still use the same credentials.
Phishing. With a valid email address in hand, scammers can craft convincing messages that reference services you actually use.
Secondary fraud. Access to an email account can enable password resets on other services, exposing financial and personal accounts to further compromise.
Researchers noted at the time that much of the data was old and had already circulated, but a compilation of this size remains a working tool for criminals, precisely because it consolidates so much material in one place.
What Should You Do If You Were Affected?
Change your passwords now. Start with your email account, then banking, shopping, and social media. If a password appears anywhere in this compilation, change it everywhere you used it.
Stop reusing passwords. Use a unique password for every account. A password manager can generate and store them for you.
Turn on two-factor authentication wherever it is offered. Even with a correct password, a second factor usually blocks a takeover.
Watch for phishing. Be skeptical of unexpected emails asking you to log in or reset a password, and go to sites directly rather than clicking links.
Review account activity. Check login histories and connected devices on your important accounts, and look for unrecognized changes.
Check your exposure.
Because this compilation draws on many older breaches, being listed does not necessarily mean a recent account was hacked. It does mean one of your old email and password combinations is in criminal hands, which is reason enough to act.
In the news
- Sophos: Credential dump contains another 2.2 billion pwned accountsnews.sophos.com (opens in a new tab)
- Wired: The biggest ever data dump just hit a colossal 2.2 billion accountswired.com (opens in a new tab)
- Comparitech: Credential Stuffing Attacks Explainedcomparitech.com (opens in a new tab)
- Group-IB: How Attackers Use Password Combolists in Brute-Force Campaignsgroup-ib.com (opens in a new tab)
