Data breach
Exploit.In
- Records
- 591,259,391
- Breach date
- 13 October 2016Estimated
- Added
- 1 December 2024
What was exposed
2 types of data · 1 puts you at serious risk
- Email addresses591,259,391
- Passwords591,206,730
About this breach
In late 2016, a massive compilation of email addresses and passwords surfaced online under the name "Exploit.In." According to our investigation team, the listing contains 591,259,391 rows, of which 591,206,730 include passwords and 591,259,391 include email addresses. The estimated date of the breach in our index is October 13, 2016. This is not a hack of a single company. It is a combo list: a collection of credentials pulled together from many earlier breaches of unrelated online services, compiled into one enormous file and shared on hacking forums.
No individual or group has publicly claimed responsibility for assembling the list, and our records show no claiming actor.
Breach Timeline
October 13, 2016: The estimated breach date in our investigation team's index, consistent with the period when the Exploit.In list is reported to have appeared.
May 6, 2017: The breach was added to Mozilla Monitor's database after being discovered and verified.
December 2017: Security researchers reported that Exploit.In credentials had been folded into an even larger collection of roughly 1.4 billion plain-text credential pairs, as covered by The Hacker News.
What Information Was Compromised?
Our analysis found the following data types in this breach: email addresses (591,259,391) and passwords (591,206,730).
Because the list is a compilation of credential pairs harvested from earlier breaches, most entries pair an email address with one or more passwords, often stored in plain text. No names, addresses, phone numbers, or payment details appear in our index for this listing.
Not every individual is affected by every type of data listed here.
What Are the Potential Risks for Affected Individuals?
The main danger from a combo list of this size is credential stuffing. Attackers take the email and password pairs in the file and automatically try them against other websites, banking on the fact that many people reuse the same password across multiple accounts. Group-IB's researchers note that Exploit.In was widely circulated and used for exactly this purpose.
If your email address and a password you have used appear in this list, attackers may try those same credentials against your email, social media, shopping, or banking accounts. Accounts protected only by a password, without two-factor authentication, are the most exposed. Attackers may also use valid-looking email addresses from such lists for phishing, since they can send messages that appear to come from or reference services you actually use.
The risk does not fade quickly. Credential lists like this one circulate for years and remain in active use by criminal groups long after the original breaches that fed them.
What Should You Do If You Were Affected?
If you believe your credentials are in this list, take the following steps:
Change your password on any account where you reused it, starting with your email account, which controls password resets for nearly everything else.
Use a unique password for every important account. A password manager can generate and store them for you.
Turn on two-factor authentication wherever it is offered, especially for email, banking, and social media.
Watch for phishing. Be cautious with emails referencing your accounts, and never enter credentials through a link in an email.
Check your accounts for unfamiliar logins or activity, and review connected apps and sessions where the service allows it.
