Around 6.5 million password hashes belonging to LinkedIn users were posted on a Russian-language forum. LinkedIn confirmed that some of the passwords were linked to its accounts.
What happened
- The passwords had been hashed with SHA-1 without salting, making many of them easy to crack.
- The posted file did not contain usernames or email addresses, but experts warned attackers might hold them separately.
- LinkedIn reset the passwords of affected accounts, emailed those users, and said it had since added salting to its password storage.
- In 2016 a much larger set of data from the same breach, covering well over 100 million accounts, was offered for sale.
Why it mattered
The breach showed the risks of outdated password storage by a major platform and became a lasting source of credentials for credential-stuffing attacks against other services, where users had reused the same passwords.
Lessons for organisations
Store passwords using modern, salted, slow hashing algorithms such as bcrypt or Argon2, and offer MFA. Staff should use unique passwords for work and personal accounts, ideally with a password manager, and organisations should check for exposed credentials after major breaches.
Sources: The Register, SANS Internet Storm Center
Part of our Top stories archive of headline-making events in information security, privacy, and AI. If you would like help applying the lessons to your organisation, contact us.