Last updated 1 month ago
In June 2026, a collection of accumulated stealer logs from various sources was added to Have I Been Pwned (HIBP), exposing 56,278,397 unique email addresses. The corpus comprised hundreds of millions of stealer log records, with 124 million unique passwords also included and added to Pwned Passwords. The disclosure date is June 2026, with no discovery date specified.
The attack vector is malware, specifically information-stealing malware that captured credentials and other data from infected systems. The data compromised includes email addresses and plaintext or hashed passwords, though the exact hashing algorithm is not specified. No specific threat actor or ransomware group is attributed, and no CVE references or MITRE ATT&CK techniques are mentioned.
No post-incident details are available regarding regulatory actions, litigation, ransom payments, or remediation milestones. The data is now searchable via HIBP, allowing individuals and organizations to check for exposed records.
Accumulated stealer logs from various sources
This breach underscores the pervasive threat of information-stealing malware, which can silently harvest credentials from infected endpoints. Organizations should enforce endpoint detection and response (EDR) solutions, implement multi-factor authentication (MFA) to mitigate credential reuse, and regularly monitor for exposed credentials in stealer logs. The scale of 56 million unique email addresses and 124 million passwords highlights the need for proactive credential hygiene and dark web monitoring.
Sign in to join the discussion.
Company
Industry
Disclosed
Records Affected
Attack Vector
Industry
Attack Vector