Tuesday, March 4, 2025
HomePassword Attacks1.4 Billion Clear Text Credentials Discovered in Underground Community Forum

1.4 Billion Clear Text Credentials Discovered in Underground Community Forum

Published on

SIEM as a Service

Follow Us on Google News

A largest dark web database discovered in Underground Community Forum that contains almost 1.4 billions clear text Credentials and this dumb data’s belongs to 252 previous breaches.

This is one of the biggest credentials database that ever discovered in history and previous largest credential exposure, the Exploit.in combo list that exposed 797 million records.

A depth research has been conducted in this database and researchers confirms that non of the passwords are encrypted and most of them have been verified to be true.

This database consists of more scary information and its working ultimately fast response (one-second response) searches and new breach imports.

According to 4iQ Reseracher, The data is organized alphabetically, offering examples of trends in how people set passwords, reuse them and create repetitive patterns over time. 
This single file database is very fastly responding to search the passwords than ever before. for an example, searching for “admin,” “administrator” and “root” returned 226,631 passwords of admin users in a few seconds.

Database file name mentioned “imported.log” with 133 addition or new breaches apart from 252 previous breaches.

Also Read: A new Hacker Group ‘MoneyTaker’ uncovered by Group-IB Attacking Banks in the USA and Russia

These are some of breach and number of password that have been leaked from the concern breaches.

Clear Text Credentials

This Database has recently updated ad 11/29/2017 was the last time this DB has updated and 41GB dump was found on 5th December 2017.

Exactly the total amount of Clear Text Credentials (usernames/clear text password pairs) is 1,400,553,869 and 14% of exposed username/passwords pairs had not previously been decrypted by the community and are now available in clear text.

“This new breach adds 385 million new credential pairs, 318 million unique users, and 147 million passwords pertaining to those previous dumps.”

These are the top 40 passwords list that has been used by the users from previous breaches.

Given the fact that people reuse passwords across their email, social media, e-commerce, banking and work accounts, hackers can automate account hijacking or account takeover.

Balaji
Balaji
BALAJI is an Ex-Security Researcher (Threat Research Labs) at Comodo Cybersecurity. Editor-in-Chief & Co-Founder - Cyber Security News & GBHackers On Security.

Latest articles

Docusnap for Windows Flaw Exposes Sensitive Data to Attackers

A recently disclosed vulnerability in Docusnap's Windows client software (CVE-2025-26849) enables attackers to decrypt...

CISA Warns of Active Exploitation of Microsoft Windows Win32k Vulnerability

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added CVE-2018-8639, a decade-old Microsoft Windows...

Update Alert: Google Warns of Critical Android Vulnerabilities Under Exploit

Google’s March 2025 Android Security Bulletin has unveiled two critical vulnerabilities—CVE-2024-43093 and CVE-2024-50302—currently under...

BigAnt Server 0-Day Vulnerability Lets Attackers Run Malicious Code Remotely

A critical vulnerability in BigAntSoft's enterprise chat server software has exposed ~50 internet-facing systems...

Supply Chain Attack Prevention

Free Webinar - Supply Chain Attack Prevention

Recent attacks like Polyfill[.]io show how compromised third-party components become backdoors for hackers. PCI DSS 4.0’s Requirement 6.4.3 mandates stricter browser script controls, while Requirement 12.8 focuses on securing third-party providers.

Join Vivekanand Gopalan (VP of Products – Indusface) and Phani Deepak Akella (VP of Marketing – Indusface) as they break down these compliance requirements and share strategies to protect your applications from supply chain attacks.

Discussion points

Meeting PCI DSS 4.0 mandates.
Blocking malicious components and unauthorized JavaScript execution.
PIdentifying attack surfaces from third-party dependencies.
Preventing man-in-the-browser attacks with proactive monitoring.

More like this

Chinese Hackers Attacking Microsoft Customers With Sophisticated Password Spray Attacks

Researchers have identified a network of compromised devices, CovertNetwork-1658, used by Chinese threat actors...

10 Best WiFi Hacking Apps for Android – 2024 Edition

In this article, we are sharing the top “Wi-Fi hacking Apps“ for Android applicants....

Brutespray – Port Scanning and Automated Brute Force Tool

Brutespray is a Python script that provides a combination of both port scanning and automated...