Data breach
web.de
- Records
- 3,534,014
- Breach date
- 1 January 2020Estimated
- Added
- 17 March 2025
What was exposed
2 types of data · 1 puts you at serious risk
- Email addresses3,534,014
- Passwords3,524,886
About this breach
The investigation team has indexed a dataset of more than 3.5 million web.de email accounts, the German mail service operated by United Internet subsidiary 1&1. According to our investigation team, the listing contains roughly 3,534,000 email addresses and nearly 3,525,000 passwords, with an estimated breach date of January 1, 2020. No individual or group has claimed responsibility for the data, and the listing does not point to a confirmed hack of web.de itself. Records like these often circulate in large credential collections assembled from many incidents and then resold or reposted on hacking forums, which makes the original source of any individual record difficult to trace.
Limited public reporting: As of September 25, 2026, detailed company notices or major news coverage for this listing were limited in sources reviewed. The facts below rely primarily on the indexed fields plus any secondary sources cited.
German reporting has documented the broader context. Heise Online noted that numerous collections of stolen login credentials circulate on the darknet, where criminals recombine and resell them. In that same reporting, a 1&1 spokesperson said GMX and web.de are exposed to internet attacks like any online service, that the company had not observed unusual attack activity, and that failed login attempts against accounts are displayed to users as a standard security notice.
What Information Was Compromised?
Our analysis found the following data types in this breach:
Email addresses: about 3,534,014 records
Passwords: about 3,524,886 records
Not every individual is affected by every type of data listed here.
The dataset contains no other personal data types according to our investigation team, so we cannot say whether names, addresses, or phone numbers were included.
What Are the Potential Risks for Affected Individuals?
Exposed email and password pairs are primarily dangerous for what criminals do with them afterward:
Credential stuffing: Attackers feed leaked email and password combinations into login forms for banking, shopping, social media, and streaming services. Anyone who reused the same password on other accounts is at direct risk of being locked out or robbed.
Account takeover: A working web.de password gives an intruder control of the mailbox. From there, an attacker can read messages, reset passwords for other services tied to that address, and impersonate the account owner.
Phishing: A real email address on its own is enough to target someone with convincing scam messages, since the criminal knows the address is active.
What Should You Do If You Were Affected?
Change your web.de password immediately if you have not done so since 2020, and choose a long, unique password.
Check whether you used that same password anywhere else, and change it on those accounts too. Reuse is the single biggest risk with leaked credentials.
Turn on two-factor authentication wherever the services you use offer it, especially for email and financial accounts.
Watch for phishing emails that reference your web.de address or account. Legitimate providers do not ask for your password by email or text.
Review the recovery options on your other accounts. If your web.de address is the backup contact for another service, an attacker who controls the mailbox can reset those logins.
