Saturday, December 7, 2024
HomeCyber Security NewsMassive Collection of 2.2 Billion Usernames and Passwords Circulated in Hacker Forums

Massive Collection of 2.2 Billion Usernames and Passwords Circulated in Hacker Forums

Published on

SIEM as a Service

A new collection of massive breached database freely distributed on hacker forums and torrents. The breached database contains a collection of 2.2 billion unique usernames and it’s passwords.

The database named Collections #2 to #5 contains 845GB of stolen data and contains 25 billion records in total.

The massive collection of the breached database was identified by security researcher Chris Rouland from torrented files. He said WIRED that the collection has already circulated widely among the underground hacker forums.

- Advertisement - SIEM as a Service

Rouland could see that the database has been downloaded for more than 1,000 times and seeded by more than 130 people.

Before two weeks a massive collection “Collection#1” found by security researcher Troy Hunt from MEGA cloud storage. The collection contains 773 million records and have merely 87GB of data.

According to WIRED, who analyzed the sample of the leaked data, the credentials appear to be valid and they from years-old leaks.

This Massive Data collection leads to the expose of email addresses and passwords which has been harvested from various other sources of different breaches of different timeframes were kept in a folder.

For those who concern that your accounts may have been compromised can use Have I Been Pwned to check that that your account information present in “Collection#1”, for Collections #2 to #5 you can check Hasso Plattner Institute tool.

You can follow us on Linkedin, Twitter, Facebook for daily Cybersecurity updates also you can take the Best Cybersecurity courses online to keep your self-updated.

Gurubaran
Gurubaran
Gurubaran is a co-founder of Cyber Security News and GBHackers On Security. He has 10+ years of experience as a Security Consultant, Editor, and Analyst in cybersecurity, technology, and communications.

Latest articles

Top Five Industries Most Frequently Targeted by Phishing Attacks

Researchers analyzed phishing attacks from Q3 2023 to Q3 2024 and identified the top...

Russian BlueAlpha APT Exploits Cloudflare Tunnels to Distribute Custom Malware

BlueAlpha, a Russian state-sponsored group, is actively targeting Ukrainian individuals and organizations by using...

Russian Hackers Hijacked Pakistani Actor Servers For C2 Communication

Secret Blizzard, a Russian threat actor, has infiltrated 33 command-and-control (C2) servers belonging to...

Sophisticated Celestial Stealer Targets Browsers to Steal Login Credentials

Researchers discovered Celestial Stealer, a JavaScript-based MaaS infostealer targeting Windows systems that, evading detection...

API Security Webinar

72 Hours to Audit-Ready API Security

APIs present a unique challenge in this landscape, as risk assessment and mitigation are often hindered by incomplete API inventories and insufficient documentation.

Join Vivek Gopalan, VP of Products at Indusface, in this insightful webinar as he unveils a practical framework for discovering, assessing, and addressing open API vulnerabilities within just 72 hours.

Discussion points

API Discovery: Techniques to identify and map your public APIs comprehensively.
Vulnerability Scanning: Best practices for API vulnerability analysis and penetration testing.
Clean Reporting: Steps to generate a clean, audit-ready vulnerability report within 72 hours.

More like this

Top Five Industries Most Frequently Targeted by Phishing Attacks

Researchers analyzed phishing attacks from Q3 2023 to Q3 2024 and identified the top...

Russian BlueAlpha APT Exploits Cloudflare Tunnels to Distribute Custom Malware

BlueAlpha, a Russian state-sponsored group, is actively targeting Ukrainian individuals and organizations by using...

Russian Hackers Hijacked Pakistani Actor Servers For C2 Communication

Secret Blizzard, a Russian threat actor, has infiltrated 33 command-and-control (C2) servers belonging to...