Trending Topics

Latest Have I Been Pwned update gives 1.3 billion new reasons to stop relying on passwords
I will readily admit that I sound like a broken record when it comes to the need to stop using magical thinking about passwords and account security. Relying upon a password to protect your data is like buying magic beans, and the beanstalk will lead to a giant that smells insecurity instead of blood. But donโt take my word for it, listen to the words of Tory Hunt, founder of the Have I Been Pwned leaked credentials database and associated Pwned Passwords service.
Speaking to the latest addition to the Have I Been Pwned database, Hunt warned: โThis corpus is nearly three times the size of the previous largest breach we’d loaded.โ You want the numbers? I hope you’re sitting down…
- 1,957,476,021 unique email addresses
- 1.3 billion unique passwords
- 625 million passwords completely new to the HIBP database
While these figures are shocking, they donโt come as any great surprise. I have already warned about the stealer logs that had been compiled by the Synthient threat intelligence platform when the original data leak was confirmed just over a week ago.
At the time, 183 million passwords were known to be part of that data collection. A massive number that has now been beaten into oblivion as the true extent of the leak becomes clear once the credential stuffing attack data is added.
โIt’s the most extensive corpus of data we’ve ever processed, by a significant margin,โ Hunt said.
One message from latest Have I Been Pwned update: don’t rely on passwords
The reason why this is so bad for anyone relying solely upon passwords to protect their accounts, networks and data is pretty clear. With stealer log data coming from successful malware infections, and credential stuffing lists originating from data breach lists exposing email and passwords, this is the skeleton key to unlock accounts where people have not truly been taking security seriously. Oh, the irony, huh?
Taking security, authentication, and your business seriously means accepting that multiple layers of defence are required to keep threat actors out. Iโve been advising the use of passkeys instead of passwords for a couple of years now, and if thatโs not yet doable, at least ensure your passwords are, as Hunt puts it, โstrong and unique,โ while backing them up by โturning on multi-factor authโ.
โAligning credential monitoring with a firmโs overall risk management framework,โ said Sachin Jade, Chief Product Officer at Cyware, โhelps organisations prioritise response based on contextual risk rather than isolated incidents.โ
Password management is key for consumers, small and large businesses alike. Donโt reuse ever. Donโt insist upon pointless regular password rotations. Donโt make security harder than it already is. The 1.3 billion consequences of doing so can be found at Have I Been Pwned.
