Massive Collection of 2.2 Billion Usernames and Passwords Circulated in Hacker Forums

A new collection of massive breached database freely distributed on hacker forums and torrents. The breached database contains a collection of 2.2 billion unique usernames and it’s passwords.

The database named Collections #2 to #5 contains 845GB of stolen data and contains 25 billion records in total.

The massive collection of the breached database was identified by security researcher Chris Rouland from torrented files. He said WIRED that the collection has already circulated widely among the underground hacker forums.

Rouland could see that the database has been downloaded for more than 1,000 times and seeded by more than 130 people.

Before two weeks a massive collection “Collection#1” found by security researcher Troy Hunt from MEGA cloud storage. The collection contains 773 million records and have merely 87GB of data.

According to WIRED, who analyzed the sample of the leaked data, the credentials appear to be valid and they from years-old leaks.

This Massive Data collection leads to the expose of email addresses and passwords which has been harvested from various other sources of different breaches of different timeframes were kept in a folder.

For those who concern that your accounts may have been compromised can use Have I Been Pwned to check that that your account information present in “Collection#1”, for Collections #2 to #5 you can check Hasso Plattner Institute tool.

You can follow us on LinkedinTwitterFacebook for daily Cybersecurity updates also you can take the Best Cybersecurity courses online to keep your self-updated.

Gurubaran

Gurubaran is a co-founder of Cyber Security News and GBHackers On Security. He has 10+ years of experience as a Security Consultant, Editor, and Analyst in cybersecurity, technology, and communications.

Recent Posts

Lotus Blossom Hacker Group Uses Dropbox, Twitter, and Zimbra for C2 Communications

The Lotus Blossom hacker group, also known as Spring Dragon, Billbug, or Thrip, has been…

2 hours ago

Squidoor: Multi-Vector Malware Exploiting Outlook API, DNS & ICMP Tunneling for C2

A newly identified malware, dubbed "Squidoor," has emerged as a sophisticated threat targeting government, defense,…

2 hours ago

Unpatched Vulnerabilities Attract Cybercriminals as EDR Visibility Remains Limited

Cyber adversaries have evolved into highly organized and professional entities, mirroring the operational efficiency of…

2 hours ago

Threat Actors Attack Job Seekers of Fortune 500 Companies to Steal Personal Details

In Q3 2024, Cofense Intelligence uncovered a targeted spear-phishing campaign aimed at employees working in…

2 hours ago

DragonForce Attacks Critical Infrastructure to Exfiltrate Data and Halt Operations

The DragonForce ransomware group has launched a significant cyberattack on critical infrastructure in Saudi Arabia,…

2 hours ago

New Malware Uses Legitimate Antivirus Driver to Bypass All System Protections

In a concerning development, cybersecurity researchers at Trellix have uncovered a sophisticated malware campaign that…

2 hours ago