Data breach
Pemiblanc
- Records
- 134,117,443
- Breach date
- 2 April 2018Estimated
- Added
- 1 December 2024
What was exposed
1 type of data · 1 more reported
- Email addresses134,117,443
- PasswordsReported, not counted
Reported in the breach write-up; not counted in the analysed data.
About this breach
In April 2018, security researchers discovered a massive credential list known as Pemiblanc stored on a French web server. The file, hosted on the pemiblanc.com domain, contained tens of millions of email address and password pairs compiled from previous data breaches and organized for use in account takeover attacks. According to our investigation team, the indexed listing contains 134,117,443 rows, though outside trackers have reported roughly 111 million credential pairs. Pemiblanc is not the result of a single hack into one company. It is a compilation, stitched together from multiple older breaches, and was apparently assembled to power credential stuffing, a technique in which attackers automatically replay leaked email and password combinations against other websites hoping people reused the same passwords.
Limited public reporting: As of [research cutoff date], detailed company notices or major news coverage for this listing were limited in sources reviewed. The facts below rely primarily on the indexed fields plus any secondary sources cited.
Breach Timeline
April 2, 2018: The Pemiblanc credential list was discovered on a French web server.
July 9, 2018: The listing was added to Mozilla Monitor's public breach database.
What Information Was Compromised?
Our analysis found the following data types in this breach: email addresses and passwords.
External trackers including Mozilla Monitor and XposedOrNot identify the exposed records as email address and password pairs, with passwords reportedly stored in plaintext. Because the list was assembled from many separate breaches, the passwords originate from a wide range of unrelated services rather than one website's database.
Not every individual is affected by every type of data listed here.
What Are the Potential Risks for Affected Individuals?
The primary danger from a credential stuffing list is account takeover. Attackers feed the email and password pairs into automated tools that try the same combinations on banking sites, social media, shopping accounts, and email providers. If you reused a password that appears in Pemiblanc on any other account, that account may be vulnerable.
Secondary risks include targeted phishing. Because the list pairs real email addresses with passwords, scammers can reference those details in messages designed to look convincing. There is no indication in available sources that the compilation included financial data, government identifiers, or other sensitive records, but the combination of a working email and password is itself enough to cause serious harm.
What Should You Do If You Were Affected?
If your email address appears in this listing, take these steps:
Change the password on any account where you used the exposed password, and change it anywhere else you reused it.
Use a unique password for every account. A password manager can generate and store strong, distinct passwords.
Turn on two-factor authentication wherever it is offered, especially for email, banking, and shopping accounts. This protects you even if a password is known.
Watch for phishing. Be cautious with emails referencing old passwords or claiming unusual account activity, and never confirm credentials through a link in a message.
Review account activity for logins or changes you do not recognize, and check whether your recovery email and phone details are still correct.
