Advertisement

Massive data breach exposes 183 million email passwords

Massive data breach exposes 183 million email passwords
A typical smartphone with apps. Photo: Pexels
Advertisement
Advertisement

A significant data exposure has compromised over 183 million email credentials, with tens of millions associated with Gmail users, in what experts are describing as one of the most substantial collections of stolen login information ever discovered.

This collection of data, amounting to 3.5 terabytes, became available online this month, as reported by Troy Hunt, an Australian security expert who operates the breach-alert service Have I Been Pwned.

Hunt stated that the information originated from a yearlong sweep of “infostealer” platforms — malware networks that secretly siphon usernames, passwords and website addresses from infected devices.

The data consists of both “stealer logs and credential stuffing lists,” Hunt wrote in a blog post.

Advertisement
Advertisement

“Someone logging into Gmail ends up with their email address and password captured against gmail.com.”

The new dataset contained 183 million unique accounts, including roughly 16.4 million addresses never seen before in any prior breach, Hunt wrote.

Individuals can check whether their login information is part of this leak by visiting HaveIBeenPwned.com and inputting their email address. If a match is found, the service will show the date and specifics of the breach.

Related News

The logs were gathered by the security company Synthient, which indicated the information was sourced from illicit online marketplaces and private Telegram groups where hackers distribute large quantities of stolen login details.

Synthient’s analyst, Benjamin Brundage, noted that the data reveals the extensive prevalence of information-stealing malicious software.

Researchers indicate that while a majority of the records are repurposed from previous incidents, millions of newly affected Gmail accounts were confirmed after users verified that the leaked passwords were still valid for their active accounts.

The most important step is prevention, Tigges said.

“Make sure your anti-virus is up to date and that you’re downloading software from reputable sources,” he said.

“These credentials were obtained primarily through ‘stealer’ type malware; prevention is the chief mitigation.”

Although the size of this data release seems unmatched, Hunt stressed that the primary danger lies in user inaction.

“Reusing passwords is a recipe for disaster,” he explained.

Specialists cautioned that the database could be exploited by malicious actors for an extended period, as validated Gmail access is sold to criminal groups.

Follow TIMES on Google News

Get trusted updates and editor-picked stories in your feed.

Follow
Related News