Data breach
126
- Records
- 7,297,524
- Breach date
- 1 January 2012Estimated
- Added
- 1 December 2024
What was exposed
2 types of data · 1 puts you at serious risk
- Email addresses7,297,524
- Passwords2,298,654
About this breach
In early 2012, the Chinese email service 126.com, a free mailbox provider operated by NetEase, was reportedly breached in an incident that exposed the account records of millions of users. The indexed dataset contains 7,297,524 records tied to the estimated attack date of January 1, 2012. Independent verification of Chinese breaches from this period has historically been difficult, and public reporting on this incident remains sparse. Mozilla Monitor lists the breach with a date of January 1, 2012, and catalogs email addresses and passwords as the compromised data.
Limited public reporting: As of September 25, 2026, detailed company notices or major news coverage for this listing were limited in sources reviewed. The facts below rely primarily on the indexed fields plus any secondary sources cited.
Breach Timeline
January 1, 2012: Mozilla Monitor dates the 126.com breach to this date.
October 8, 2016: Mozilla Monitor added the breach to its public database after verifying it.
What Information Was Compromised?
Our analysis found the following data types in this breach:
Email addresses: 7,297,524 records. These are the 126.com mailbox addresses of affected users.
Passwords: 2,298,654 records. Not every record in the dataset includes a password, so a substantial portion of the listed email addresses appears without associated credentials.
Not every individual is affected by every type of data listed here.
The combination of an email address and a password is the core risk in any credential leak. Because the affected accounts are email accounts themselves, exposure can extend beyond the mailbox if the same password protected other services.
What Are the Potential Risks for Affected Individuals?
The most immediate risk is account takeover. Anyone holding a valid 126.com email address and matching password can attempt to log in to the mailbox, read stored messages, and use password reset flows to seize other accounts linked to that address.
Credential reuse compounds the problem. If a person used the same password on 126.com as on shopping, banking, or social media accounts, leaked credentials can be replayed against those services in automated credential stuffing attacks.
Email access also enables phishing. An attacker who controls a mailbox can intercept password reset emails for other services and can send convincing messages from a trusted address to the victim's contacts.
Even email addresses alone carry risk. They can be used for targeted phishing, spam, and attempts to socially engineer recipients.
What Should You Do If You Were Affected?
If you had a 126.com address and believe your details may be in this dataset, take the following steps:
Change your 126.com password immediately. If you no longer use the mailbox, it is still worth securing or recovering the account so it cannot be taken over by someone else.
Change that password everywhere else you used it. Reused passwords are the fastest route from a single leak to multiple compromised accounts.
Enable two-factor authentication on 126.com and on your other important accounts, especially email, banking, and social media.
Review account activity. Check for unfamiliar logins, sent messages you did not write, or password reset emails you did not request.
Update recovery details. Make sure the recovery email and phone number on your key accounts are current and that the mailbox is not the sole recovery route.
Stay alert to phishing. Emails or messages that reference your account and urge urgent action may be attempts to harvest fresh credentials.
No claiming individual or group is attributed in the indexed data.
