A massive trove of 361 million email addresses from credentials stolen by password-stealing malware, in credential stuffing attacks, and from data breaches was added to the Have I Been Pwned data breach notification service, allowing anyone to check if their accounts have been compromised.

With a dataset this large, no site that allows logins is unaffected by these leaked credentials

@gedaliyah@lemmy.world
creator
link
fedilink
English
34M

That’s a third of a billion

Victor
link
fedilink
English
144M

no site that allows logins is unaffected

Why these double negatives.

all sites that allow logins are affected

@Plopp@lemmy.world
link
fedilink
English
44M

I like how the article has several links to things it mentions, but doesn’t link to Have I Been Pwned at all even though that’s the key site of the whole thing and where the reader should go to see if they’re affected. Well done, article.

Create a post

This is a most excellent place for technology news and articles.


Our Rules


  1. Follow the lemmy.world rules.
  2. Only tech related content.
  3. Be excellent to each another!
  4. Mod approved content bots can post up to 10 articles per day.
  5. Threads asking for personal tech support may be deleted.
  6. Politics threads may be removed.
  7. No memes allowed as posts, OK to post as comments.
  8. Only approved bots from the list below, to ask if your bot can be added please contact us.
  9. Check for duplicates before posting, duplicates may be removed

Approved Bots


  • 1 user online
  • 182 users / day
  • 580 users / week
  • 1.37K users / month
  • 4.49K users / 6 months
  • 1 subscriber
  • 7.41K Posts
  • 84.7K Comments
  • Modlog