Skip to main content
Breach Signal

Breach report

Credential Compilation

Collection #1

773M Password 'Megabreach' is Years Old

An 87-gigabyte trove dubbed Collection #1 aggregated 773 million unique email addresses and 21 million passwords from thousands of older breaches, becoming the biggest load ever added to Have I Been Pwned at the time.

Reported by Krebs on Security

Records exposed

773M

773 million unique email addresses and 21 million unique passwords

Scale vs. largest on file

When
2019
How they got in
Aggregation of credentials from thousands of prior breaches, shared on a public file host and hacking forums
Sector
Credential Compilation

In mid-January 2019, security researcher Troy Hunt, who runs the breach notification service Have I Been Pwned, announced that he had loaded a massive credential dump known as Collection #1. The data, originally hosted on the file-sharing service Mega and circulated on hacking forums, consisted of about 12,000 files totaling 87 gigabytes and more than 2.7 billion rows of email and password combinations. Hunt said he learned of the files after several people contacted him about them, and that his own email address and an old password appeared in the set.

After removing duplicates, Hunt counted about 773 million unique email addresses and roughly 21 million unique passwords, many stored in plaintext. It was the single largest breach he had ever added to the service. Unlike a traditional breach, Collection #1 did not come from one company. It was a compilation assembled from thousands of earlier leaks, the kind of list criminals use for credential stuffing attacks that test reused passwords against other websites.

Reporting by Brian Krebs found that the seller, who went by the name Sanixer, described Collection #1 as at least two or three years old and part of a larger offering. The seller advertised additional sets, later known as Collections #2 through #5, totaling several hundred gigabytes and billions more records. Threat intelligence firms said much of Collection #1 already existed in their databases, which tempered claims that it represented a fresh compromise.

There were no fines or corporate defendants because no single organization was responsible. The practical fallout landed on individuals: millions of people learned through Have I Been Pwned and media coverage that their email address and a password were in circulation. Password managers and browsers expanded breach-checking features, and Hunt's companion Pwned Passwords service, which lets sites block known compromised passwords, saw heavy use.

Collection #1 helped mainstream the idea that the main danger of old breaches is password reuse. A credential stolen from a defunct forum years ago can still unlock an email, shopping or banking account today if the same password is used. The standard advice that followed, using a unique password for every site and enabling multi-factor authentication, remains the most effective defense against these compilations.

More from the wire

More in Credential Compilation.

All 107 reports

Private AI for Life

Live your best life with Thinkspan: the all-in-one smart solution for organizing, securing, and accessing personal information. With Thinkspan, your life’s most important information stays protected and accessible.