15.01.2019

New data incident: 2.2 billion online accounts affected

After the most recent incident, in which it became known that millions of hacked email addresses and passwords are circulating in Internet forums under the name “Collection #1”, the remaining parts “Collection #2 – #5” have now appeared.

What happened?

As the name Collection #1 suggested, there are apparently other parts in addition to this data set with 21,222,975 passwords and 772,904,991 email addresses. The Hasso Plattner Institute announced today that it has prepared the dataset Collection #1 and the remaining parts #2 – #5 and incorporated them into its “Identity Leak Checker” service.

The data collections comprise 2.2 billion e-mail addresses with passwords. The user information contained in it was stolen at an unknown time, compiled and posted on the Internet. Some of the information comes from already known security incidents. Nevertheless, it is worth being sure and checking your own e-mail address again.

A security expert who prepared the Data Set Collection #1 suspects that this part was intended for so-called “credential stuffing”. This is the automated use of revealed username and password combinations. This makes it possible to gain access to user accounts and, if necessary, take over them completely.