Data breach
- Records
- 77,542,528
- Breach date
- 5 May 2012Estimated
- Added
- 1 December 2024
What was exposed
2 types of data · 1 puts you at serious risk
- Email addresses77,542,528
- Passwords54,764,309
About this breach
In 2012, LinkedIn suffered one of the largest breaches of its era. According to our investigation team, the indexed dataset contains more than 77.5 million records, including about 77.5 million email addresses and roughly 54.8 million passwords. The team estimates the attack took place around May 5, 2012, though the breach did not become public until weeks later, when stolen password data began appearing online. What LinkedIn initially described as a limited incident later turned out to be far larger. Four years after the breach, a far bigger cache of stolen LinkedIn credentials surfaced for sale on a dark web marketplace, and LinkedIn acknowledged the theft extended well beyond the accounts it had reset in 2012.
Breach Timeline
June 5, 2012: LinkedIn was hacked, and passwords for nearly 6.5 million user accounts were posted to a Russian web forum, where attackers encouraged others to help crack the unsalted SHA-1 hashed passwords. LinkedIn forced password resets for affected accounts, according to Wikipedia's account of the incident and BBC News.
May 18, 2016: A hacker using the alias "Peace" put email and password combinations for roughly 117 million LinkedIn members up for sale on the dark web marketplace The Real Deal for about $2,200 in bitcoin. Reporting by TechCrunch and The Guardian tied the data to the same 2012 theft, and LinkedIn responded by invalidating the passwords of accounts that had not changed theirs since 2012.
What Information Was Compromised?
Our analysis found the following data types in this breach:
Email addresses: approximately 77.5 million records
Passwords: approximately 54.8 million records
The passwords in the 2012 theft were protected with SHA-1 hashing but without salt, a weakness that made them much easier to crack. When the larger cache surfaced in 2016, analysts reported that about 90 percent of the passwords had been cracked within 72 hours, according to TechCrunch.
Not every individual is affected by every type of data listed here.
What Are the Potential Risks for Affected Individuals?
The main danger from this breach is password reuse. If you used the same password on LinkedIn as on your email, banking, or social media accounts, criminals can try those credentials elsewhere until one works. Security researchers documented exactly this pattern after the 2012 breach, when attackers cracked large numbers of the leaked passwords quickly.
There is also a phishing risk. BBC News reported that scammers sent emails pretending to be from LinkedIn shortly after the breach, asking users to confirm their email addresses through links that led to sites selling counterfeit drugs. Because the stolen data pairs real email addresses with passwords, it remains useful material for convincing phishing messages years later.
What Is LinkedIn Doing in Response?
LinkedIn took action in both waves of the incident. In 2012, the company confirmed the breach on its official blog, forced password resets for accounts it believed were compromised, and emailed affected members with reset instructions, according to BBC News. In May 2016, after the larger dataset surfaced, LinkedIn Chief Information Security Officer Cory Scott said the company was invalidating the passwords of all impacted accounts that had not been changed since 2012 and contacting those members to reset them. He stated the company had no indication the 2016 disclosure resulted from a new breach, per Fortune.
What Should You Do If You Were Affected?
Change your LinkedIn password if you have not done so since 2012.
Change that password anywhere else you reused it, starting with email and banking accounts.
Turn on two-step verification for LinkedIn and your other important accounts.
Watch for phishing emails that claim to come from LinkedIn, and avoid clicking links in unexpected messages. Go directly to linkedin.com instead.
Check whether your email address appears in this or other breaches using the search tool.
In the news
- 2012 LinkedIn hack, Wikipediaen.wikipedia.org (opens in a new tab)
- BBC News, LinkedIn users targeted in email scam after hack (2012)bbc.com (opens in a new tab)
- TechCrunch, 117 million LinkedIn emails and passwords from a 2012 hack just got posted online (2016)techcrunch.com (opens in a new tab)
- The Guardian, Hacker advertises details of 117 million LinkedIn users on darknet (2016)theguardian.com (opens in a new tab)
- Fortune, LinkedIn lost 167 million account credentials in data breach (2016)fortune.com
