Latest Have I Been Pwned update gives 1.3 billion new reasons to stop relying on passwords

I will readily admit that I sound like a broken record when it comes to the need to stop using magical thinking about passwords and account security. Relying upon a password to protect your data is like buying magic beans, and the beanstalk will lead to a giant that smells insecurity instead of blood. But donโ€™t take my word for it, listen to the words of Tory Hunt, founder of the Have I Been Pwned leaked credentials database and associated Pwned Passwords service.

Speaking to the latest addition to the Have I Been Pwned database, Hunt warned: โ€œThis corpus is nearly three times the size of the previous largest breach we’d loaded.โ€ You want the numbers? I hope you’re sitting down…

  • 1,957,476,021 unique email addresses
  • 1.3 billion unique passwords
  • 625 million passwords completely new to the HIBP database

While these figures are shocking, they donโ€™t come as any great surprise. I have already warned about the stealer logs that had been compiled by the Synthient threat intelligence platform when the original data leak was confirmed just over a week ago.

At the time, 183 million passwords were known to be part of that data collection. A massive number that has now been beaten into oblivion as the true extent of the leak becomes clear once the credential stuffing attack data is added.

โ€œIt’s the most extensive corpus of data we’ve ever processed, by a significant margin,โ€ Hunt said.

One message from latest Have I Been Pwned update: don’t rely on passwords

The reason why this is so bad for anyone relying solely upon passwords to protect their accounts, networks and data is pretty clear. With stealer log data coming from successful malware infections, and credential stuffing lists originating from data breach lists exposing email and passwords, this is the skeleton key to unlock accounts where people have not truly been taking security seriously. Oh, the irony, huh?

Taking security, authentication, and your business seriously means accepting that multiple layers of defence are required to keep threat actors out. Iโ€™ve been advising the use of passkeys instead of passwords for a couple of years now, and if thatโ€™s not yet doable, at least ensure your passwords are, as Hunt puts it, โ€œstrong and unique,โ€ while backing them up by โ€œturning on multi-factor authโ€.

โ€œAligning credential monitoring with a firmโ€™s overall risk management framework,โ€ said Sachin Jade, Chief Product Officer at Cyware, โ€œhelps organisations prioritise response based on contextual risk rather than isolated incidents.โ€

Password management is key for consumers, small and large businesses alike. Donโ€™t reuse ever. Donโ€™t insist upon pointless regular password rotations. Donโ€™t make security harder than it already is. The 1.3 billion consequences of doing so can be found at Have I Been Pwned.

More security articles by Davey Winder

Avatar photo
Davey Winder

With four decades of experience, Davey is one of the UK's most respected cybersecurity writers and a contributing editor to PC Pro magazine. He is also a senior contributor at Forbes. You can find him at TechFinitive covering all things cybersecurity.