A logo for soteria technology solutions with a spartan helmet

The Hits Just Keep Coming

Erin Patten • July 8, 2024

Gigantic Password leaks keep rolling in; and they keep getting bigger.


How can you keep your accounts safe?

In early January this year, it was reported that a dataset including the leaked credentials of over 71 MILLION unique passwords was spotted available for purchase on the dark web. 


That in itself isn't unusual, big lists show up all the time, but they are usually mostly repackaged information that has been circulating for a while.  This one was different - not only was it huge, over a third of the information was new.


Later that month, a leak SO HUGE, researchers called it the Mother of All Breaches, released 26 BILLION records.

These records included logins from a wide range of popular websites, including Twitter, LinkedIn, Adobe,

Canva, Evite, AdultFriendFinder and dozens more.   Compare that to one researcher's data leak checker, which contained records from all the biggest leaks - and only totaled 15 billion records.


Now just a few months later, another huge breach was detected, this one leaking 10 BILLION unique passwords.


Threat actors can use all that data for a wide range of attacks, starting with credential stuffing, where attackers use leaked credentials to gain access - either through passwords that haven't been changed yet, or by trying the same password sets against lots of different sites - in the hopes that that person reused that password for other accounts. Other possible attacks could include identity theft, targeted phishing schemes, and other sophisticated cyberattacks.



So what can you do???


The first step is knowing that at these leaks exist, and that you probably have one or more affected accounts.

The next step is doing something about it. Frankly, every solution is kind of a pain in the butt.

But it is so important to do it, and keep doing it, to try to stay ahead of the attackers.


Have I Been Pwned? https://haveibeenpwned.com/  is a free online tool you can use to check if your email or password has been part of a breach.  You can also have the site notify you if your email shows up in a future breach. While it is not a complete catalog of every breach ever, it is one of the oldest, best, easiest tools you can use. As they say in their FAQ, "Whilst HIBP is kept up to date with as much data as possible, it contains but a small subset of all the records that have been breached over the years. Many breaches never result in the public release of data and indeed many breaches even go entirely undetected. "Absence of evidence is not evidence of absence" or in other words, just because your email address wasn't found here doesn't mean that is hasn't been compromised in another breach."


Use a Password Vault to Create and Remember New, Difficult Passwords: A password vault like 1Password, Keeper, or even Apple's iCloud can set and recall unique, long, hard-to-crack passwords for you.  Most browsers will do this to some extent also, but may not be as secure. Some services include leak checking, and some will prompt you to reset aging passwords regularly. Do your research and choose the right vault for you.


Use MFA if Possible: MFA (multi-factor authorization) uses a secondary method to verify if every login is indeed coming from you. It usually uses something you own, like a text or app on your phone, or a special key, to add a second layer of protection.  MFA will stop all but the most persistent attacks in their tracks. Read more about MFA here.


Change your Passwords: If one of your accounts appears on a list of leaks, CHANGE THAT PASSWORD IMMEDIATELY.  Then change the passwords on any accounts using the same or similar passwords.  Absolutely DO NOT just add a 1 to the end of the old password - come up with something completely new. See this blog post for tips on creating good passwords (or get a vault as previously suggested.) If you tend to reuse similar passwords, or your passwords are several years old - it might be a good idea to go ahead and change all your passwords.  I did mention this would be a pain in the butt.  It's worth it, I promise.


Great! Now Do it Again: If only this was a one-and done thing, it would be nice, but breaches happen continually.  Set a reminder on your calendar to check haveibeenpwned.com once a month, and/or to change any aging or sensitive passwords (such as for bank accounts) at that time also.


This post, like all our posts, is 100% written by a human.

Share this Post

A woman hides her face behind a library book
December 10, 2024
A rare win this month, these scammers are in trouble.
a book with fanned pages and blurry background
By Erin Patten November 20, 2024
Revisiting the Ghost Books Scam - with real-world consequences.
The insightly podcast logo
November 1, 2024
Tariq talks all things cybersecurity with the podcast hosts Alyssa and Jordan.
the silhouette of a woman's face is covered with a projection of green computer code
September 30, 2024
A freely accessible database containing full background data for about a third of all Americans was just uncovered on the internet.
A new two-story home with a soft pink and blue sunset in the background.
August 28, 2024
Real Estate scams and wire fraud costs Americans hundreds of millions of dollars every year. One victim shares her story.
A 19th century engraving of three rough and hungry looking children searching for potatoes.
July 24, 2024
A look at what insights history can offer us about how things like this happen.
A screenshot from KSN Channel 3, of a newscaster speaking in front of a screen showing computer code
June 24, 2024
Cyberattacks have led to an outage in the software car dealerships across North America use to run their operations - making dealerships rely on pen and paper again, and putting untold amounts of personal data at risk.
A robot hand explores a blue imagined universe of connected webs of dots
By Erin Patten June 17, 2024
Researchers recently proved that GPT-4 can find and exploit unknown security weaknesses - by itself. It's a whole new world for cybersecurity.
A man flips a coin into the air
By Erin Patten June 12, 2024
Between fake job postings and fake applicants, the job market is a rough place to be.
More Posts
Share by: