Security researcher Troy Hunt revealed a vast credential dump dubbed Collection #1, which had been shared on the MEGA file-hosting service and on hacking forums. He loaded around 773 million unique email addresses into Have I Been Pwned, making it the largest single addition to the service at the time.
What happened
- The collection held more than 2.69 billion rows of email addresses and passwords spread across over 12,000 files totalling about 87GB.
- Around 21 million unique passwords were extracted, roughly half of which had not been seen in Pwned Passwords before.
- The data was aggregated from many earlier breaches rather than a single new incident, and was designed for credential stuffing.
- About 140 million of the email addresses had not previously appeared in Have I Been Pwned.
Why it mattered
Collection #1 showed how old breaches are recycled into ready-made lists for automated account takeover, putting anyone who reuses passwords at risk long after the original incident. It also demonstrated the value of breach notification services that let individuals check whether their details have been exposed.
Lessons for organisations
Enforce multi-factor authentication, screen new passwords against known breached lists, and monitor for credential stuffing against login pages. Encourage staff to use password managers so that each service has a unique password.
Source: Troy Hunt
Part of our Top stories archive of headline-making events in information security, privacy, and AI. If you would like help applying the lessons to your organisation, contact us.