Data breach
NetEase
- Records
- 259,802,695
- Breach date
- 19 October 2015Estimated
- Added
- 1 December 2024
What was exposed
2 types of data · 2 more reported · 1 puts you at serious risk
- Email addresses259,802,695
- Passwords259,499,351
- UsernamesReported, not counted
- Security questionsReported, not counted
Reported in the breach write-up; not counted in the analysed data.
About this breach
NetEase, one of China's largest email providers, was linked to a massive credential leak in October 2015. According to our investigation team, the listing tied to the 163.com domain contains roughly 259.8 million records, including about 259.5 million passwords. Reporting at the time indicated that email addresses and plaintext passwords for some 235 million accounts from NetEase's 163.com and 126.com services were being offered for sale on a dark web marketplace by a vendor known as DoubleFlag, who was simultaneously selling data attributed to other major Chinese internet companies. NetEase has maintained that no breach of its systems occurred, a position it has kept even as independent researchers found the data itself appeared legitimate.
What Information Was Compromised?
Our analysis found the following data types in this breach: email addresses (259,802,695) and passwords (259,499,351).
Contemporary reporting, including coverage by CSO Online, described the passwords as being stored in plaintext. Some later summaries of the incident, such as one compiled by Huntress, also list usernames and security question answers among the exposed data, though the underlying source data for those fields is harder to verify.
Not every individual is affected by every type of data listed here.
What Are the Potential Risks for Affected Individuals?
Because the passwords reportedly appeared in plaintext, the most immediate risk is account takeover. Anyone whose email address and password pair is in this dataset could have that mailbox accessed by an attacker.
The risk compounds because email accounts are often the recovery point for other services. Attackers who control an inbox can trigger password resets on banking, shopping, gaming, or social media accounts tied to that address. Credential stuffing is a further concern: if affected users reused the same password on other sites, criminals can automate attempts to log in with these leaked pairs across many platforms. Finally, a working email account is valuable for phishing, since attackers can impersonate the victim or harvest contacts for convincing follow-up scams.
What Is NetEase Doing in Response?
NetEase has denied that a breach occurred. CSO Online reported that the company "has maintained that no data breach occurred," and other outlets noted the incident went unacknowledged despite the data circulating among dark web sellers. As of September 25, 2026, we found no verified notice from NetEase instructing affected users to reset passwords, and no independent confirmation of how the data was originally obtained. The uncertainty here matters: the dataset's contents appear genuine based on secondary reporting, but the company's position and the lack of a confirmed intrusion vector mean readers should treat the details above as reported, not settled.
What Should You Do If You Were Affected?
Change your 163.com or 126.com email password immediately if you have not done so since 2015. Choose a long, unique password you do not use anywhere else.
Change the passwords of any other accounts that used the same or a similar password, starting with banking, payment, and gaming accounts linked to the email address.
Turn on two-factor authentication wherever the email provider and other services offer it, so a stolen password alone cannot grant access.
Review the account's recovery settings, including any linked phone numbers or backup addresses, to make sure an attacker cannot redirect them.
Be cautious with unexpected emails referencing your NetEase account; attackers holding real credentials often use them to craft convincing phishing messages.
In the news
- CSO Online, "The 20 biggest data breaches of the 21st century"csoonline.com (opens in a new tab)
- CIO Africa, "The 15 Biggest Data Breaches Of The 21st Century"cioafrica.co (opens in a new tab)
- Huntress, "27 Biggest Data Breaches in History"huntress.com (opens in a new tab)
- Breachsense, "The 20 Biggest Data Leak Cases Revealed"breachsense.com (opens in a new tab)
