惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

P
Proofpoint News Feed
V
V2EX
WordPress大学
WordPress大学
Google DeepMind News
Google DeepMind News
Martin Fowler
Martin Fowler
小众软件
小众软件
Blog — PlanetScale
Blog — PlanetScale
月光博客
月光博客
The Cloudflare Blog
T
Tailwind CSS Blog
H
Help Net Security
腾讯CDC
爱范儿
爱范儿
人人都是产品经理
人人都是产品经理
H
Hackread – Cybersecurity News, Data Breaches, AI and More
The GitHub Blog
The GitHub Blog
Microsoft Security Blog
Microsoft Security Blog
Stack Overflow Blog
Stack Overflow Blog
D
DataBreaches.Net
C
Check Point Blog
量子位
酷 壳 – CoolShell
酷 壳 – CoolShell
美团技术团队
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com

Forbes - Innovation

Why Do Humans Have Fingerprints? Hint: It’s Not What You Think Booking.com Confirms Data Breach, Reservation PIN Codes Changed Why Major News Sites Are Blocking The Internet Archive’s Wayback Machine iPhone Fold Release Date: New Report Details Frustrating Apple News Comet Tracker: How To See Pan-STARRS And Three Planets On Wednesday NYT Mini Crossword Today: Tuesday, April 14 Hints And Answers Today’s NYT Strands Hints, Spangram, Answers: Tuesday, April 14 (It’s A Little Unclear) Today’s Wordle #1760 Hints And Answer For Tuesday, April 14 Most Of The Microplastics In Urban Air Come From Tires Today’s Wordle #1759 Hints And Answer For Monday, April 13 NYT Mini Crossword Today: Monday, April 13 Hints And Answers NYT Pips Today: Hints, Answers And Walkthrough For Monday, April 13 The YC Chief Who Codes 10,000 Lines A Day Has A Simple Secret Samsung Expands One UI 8.5 Beta To More Galaxy Owners Why You Should Stop Using Your iPhone If It’s On This List Chamath Says Firms That Treat AI As A Strategy Hand Rivals Their Edge 3 Unexpected Habits Of Secure Couples, By A Psychologist The First Lamp That Folds Your Clothes Samsung’s Disappointing Price Update For Galaxy Phone Buyers 3 Subtle Signs Someone Is Falling In Love With You, By A Psychologist Do Mantis Shrimp See More Colors Than Humans? A Biologist Explains NYT Connections Answers Explained For Monday, April 13 (#1,037) NYT Connections Hints Today: Monday, April 13 Clues And Answers (#1,037) LEGO Luigi & Mach 8 (72050) Review: 2026’s Best Set Yet? Marc Andreessen Says AI Productivity Will Trigger A Hiring Boom 3D Printing Is The Ultimate Hack To Reduce Household Spending Apple iPhone Fold: Striking Design Revealed In Leaked Photos Apple Smart Glasses: New Leak Reveals A Major Design Twist To Beat Meta Tested: The AI Coming To The Rivian R2 Quordle Hints Today: Monday, April 13 Clues And Answers
124 Million Unique Passwords Exposed In New Infostealer L...
Davey Winder · 2026-06-18 · via Forbes - Innovation
PAsswrod in yellow, highlighted amiong a background of blue zeros, ones and padlocks.

124 million unique password confirmed in new infostealer database.

getty

A dataset containing more than 56 million email addresses and 124 million unique passwords was added to the Have I Been Pwned database of compromised credentials on June 15. The staggering volume of stolen passwords was compiled from “hundreds of millions of stealer log records,” according to HIBP. This latest dataset, however, has not resulted from a new breach of any specific service or platform. Instead, it is a compilation of credentials from previous infostealer malware attacks, all in one place, available as a corpus of login data for cybercriminals to access and use in new exploits. Here’s what you need to know and do.

ForbesMy Password Has Been Stolen—What Happens Next?

Millions Of Passwords Included In New Infostealer Log Compilation

Infostealers are a kind of malware designed, as the name would suggest, to steal information; specifically, login credentials including passwords and authentication tokens. That there are so many logs of successful infostealer attacks is hardly surprising when you consider that malware-as-a-service platforms have lowered the barrier to entry for such threats to the point where anyone willing to pay a fee can execute them. According to KELA, a threat intelligence platform, almost 4 million unique devices were infected with infostealer malware during 2025, collectively yielding 347.5 million compromised credentials. When you added in compromised credentials from sources including databases of infostealer logs, however, KELA put that total at 2.86 billion records in all.

Although it has not been disclosed precisely where the new dataset of infostealer logs originated or which malware was used in the original attacks, the fact that there are 124 unique passwords and 56 million unique emails should be cause for concern. This type of information can be used in what are known as credential stuffing attacks, where cybercriminals use software to try known legitimate passwords against multiple accounts associated with any given email address. If you have used the same password across different accounts or services that have been compromised in an attack on one of them, even if you have since changed your details for logging into the breached account, they are all now at risk if included in this latest corpus of stolen credential information.

Check your passwords now at HIBP

Davey Winder

HIBP recommended that you either search the Pwned Passwords database for specific passwords or use the HIBP dashboard to view any records that have been aligned with your email address. If any passwords are found to have been included, then you should change them immediately, assuming you have not done so already, if it is an old breach that you were already aware of, and apply two-factor authentication if it is available for your account.

To which I would add, drawing on more than 35 years of cybersecurity experience, use a password manager: this will enable you to employ strong and unique passwords without needing to remember them all. And finally, switch to using a passkey if the option is available, as they are much harder to compromise and will not appear in these kinds of infostealer log collections.