Hackers Now Have Access to 10 Billion Stolen Passwords (2024)

Jake Peterson

Hackers Now Have Access to 10 Billion Stolen Passwords (1)

Credit: Tada Images/Shutterstock

Data leaks are an inevitability of the digital age. It's all but impossible to have accounts online without losing some of your passwords to these attacks (which is why using 2FA is so important). But it's one thing to know some of your passwords are out there somewhere; it's another thing entirely to know there are billions of our passwords conveniently rounded up for the taking.

That's exactly what new research seems to suggest: As reported by TechRadar, researchers say they found a text file, called rockyou2024.txt, containing nearly 10 billion unique passwords, all stored in plain text. That means anyone with access could scrape the list as they would a PDF and discover each and every password for themselves.

This was not a project that happened overnight: These passwords were collected over time, from various attacks and leaks over the past 20 years. Attackers added 1.5 billion of these passwords to the file from 2021 to this year alone. The fact that these are all unique, too, means there are no repeats in the list. It's tough to wrap your head around that many passwords.

What's the danger with these password leaks?

While it's bad enough that anyone with the list can Command+F their way into searching for any password under the sun, that's not really where the danger lies. It would simply take too long to look for specific passwords to try.

Rather, bad actors can use lists like this one to engage in brute force and credential stuffing attacks. In a brute force attack, bad actors try a large number of passwords in quick succession to try to break into an account. Credential stuffing is similar, but involves using leaked credentials—like known username/password combinations—with other accounts, as people tend to use the same password for multiple accounts. (Please don't do this.)

Bad actors don't run these attacks by hand, of course: They use computers, which can try millions of these passwords in an attempt to break into these accounts. With a database of 10 billion unique passwords, hackers will certainly have a field day running brute force and credential stuffing attacks against both individuals and organizations alike.

How to protect yourself from this password database

Hopefully, organizations take the time to shore up their defenses against attacks like these, but even as individuals, there's quite a bit we can do to protect ourselves.

First, you can use a leaked password checker to see if your credentials are available for bad actors to use, whether that's in this database or elsewhere. If you see that any of your passwords have been compromised, change them immediately.

On that note, make sure you're using a strong and unique password for every single one of your accounts. In the event an account's credentials are leaked, bad actors won't be successful in credential stuffing, as your other accounts won't use that compromised password.

If an account supports passkeys, use that instead, as passkeys have no credentials to leak. If not, use two-factor authentication whenever possible. In the event that bad actors know your credentials, they won't be able to break into your account without access to your trusted device, whether that's a smartphone or an authenticator app.

To manage all these credentials, use a password manager. Not only will a good password manager help you, um, manage your passwords, it should come with convenient security features, like password generators, 2FA codes, and alerts when your passwords are leaked.

Hackers Now Have Access to 10 Billion Stolen Passwords (2)

Jake Peterson

Senior Technology Editor

Jake Peterson is Lifehacker’s Senior Technology Editor. He has a BFA in Film & TV from NYU, where he specialized in writing. Jake has been helping people with their technology professionally since 2016, beginning as technical specialist at New York’s 5th Avenue Apple Store, then as a writer for the website Gadget Hacks. In that time, he wrote and edited thousands of news and how-to articles about iPhones and Androids, including reporting on live demos from product launches from Samsung and Google. In 2021, he moved to Lifehacker and covers everything from the best uses of AI in your daily life to which MacBook to buy. His team covers all things tech, including smartphones, computers, game consoles, and subscriptions. He lives in Connecticut.

Read Jake's full bio

More by Jake

AI

This Company Wants to Onboard 'AI Employees,' Whatever That Means

Apple

This Spyware Warning From Apple Is Actually Real

Related Articles

iPhone's New Passwords App Makes Two-Factor Authentication Easier

How to Store All Your Passwords in Your Mac's Menu Bar

Apple Might Get Fined $38 Billion

You Can Now Share Passwords With Your Google Family Group

Hackers Now Have Access to 10 Billion Stolen Passwords (2024)
Top Articles
eWillys | Your source for Jeep and Willys deals, mods and more
BR24 - Hier ist Bayern
Bleak Faith: Forsaken – im Test (PS5)
Lorton Transfer Station
Ffxiv Palm Chippings
Tyrunt
Ribbit Woodbine
Phillies Espn Schedule
Cnnfn.com Markets
Premier Reward Token Rs3
Craigslist Edmond Oklahoma
Jenn Pellegrino Photos
Troy Bilt Mower Carburetor Diagram
St Maries Idaho Craigslist
Zack Fairhurst Snapchat
Talbots.dayforce.com
Petco Vet Clinic Appointment
Poe Str Stacking
O'Reilly Auto Parts - Mathis, TX - Nextdoor
A Person That Creates Movie Basis Figgerits
Galaxy Fold 4 im Test: Kauftipp trotz Nachfolger?
Valic Eremit
Troy Gamefarm Prices
Sherburne Refuge Bulldogs
1145 Barnett Drive
HP PARTSURFER - spare part search portal
Noaa Marine Forecast Florida By Zone
Uky Linkblue Login
Warn Notice Va
Boneyard Barbers
Chicago Pd Rotten Tomatoes
Siskiyou Co Craigslist
15 Downer Way, Crosswicks, NJ 08515 - MLS NJBL2072416 - Coldwell Banker
Nextdoor Myvidster
Chase Bank Cerca De Mí
Help with your flower delivery - Don's Florist & Gift Inc.
Edict Of Force Poe
Hell's Kitchen Valley Center Photos Menu
Gpa Calculator Georgia Tech
Überblick zum Barotrauma - Überblick zum Barotrauma - MSD Manual Profi-Ausgabe
Ashoke K Maitra. Adviser to CMD's. Received Lifetime Achievement Award in HRD on LinkedIn: #hr #hrd #coaching #mentoring #career #jobs #mba #mbafreshers #sales…
Daly City Building Division
Dcilottery Login
Author's Purpose And Viewpoint In The Dark Game Part 3
Dragon Ball Super Super Hero 123Movies
Chubbs Canton Il
Rite Aid | Employee Benefits | Login / Register | Benefits Account Manager
552 Bus Schedule To Atlantic City
Page 5747 – Christianity Today
4Chan Zelda Totk
Understanding & Applying Carroll's Pyramid of Corporate Social Responsibility
Latest Posts
Article information

Author: Tish Haag

Last Updated:

Views: 6330

Rating: 4.7 / 5 (47 voted)

Reviews: 94% of readers found this page helpful

Author information

Name: Tish Haag

Birthday: 1999-11-18

Address: 30256 Tara Expressway, Kutchburgh, VT 92892-0078

Phone: +4215847628708

Job: Internal Consulting Engineer

Hobby: Roller skating, Roller skating, Kayaking, Flying, Graffiti, Ghost hunting, scrapbook

Introduction: My name is Tish Haag, I am a excited, delightful, curious, beautiful, agreeable, enchanting, fancy person who loves writing and wants to share my knowledge and understanding with you.