Breach report
Social Media117 million LinkedIn emails and passwords from a 2012 hack just got posted online
A 2012 LinkedIn intrusion thought to affect 6.5 million users turned out to include 117 million email and password pairs, which resurfaced for sale in 2016. A Russian hacker was later convicted in the US.
Reported by TechCrunch
Records exposed
117M
117 million email and password combinations
Scale vs. largest on file
- When
- 2012 (full scope disclosed 2016)
- How they got in
- Network intrusion; weakly hashed passwords later cracked
- Sector
- Social Media
In June 2012, LinkedIn confirmed that hackers had stolen and posted roughly 6.5 million hashed passwords. At the time the company believed the damage was contained. Four years later, in May 2016, a seller using the name "Peace" advertised a far larger haul on a dark web marketplace: about 167 million LinkedIn account records, of which some 117 million included both an email address and a password hash, offered for a few thousand dollars in bitcoin.
The root problem was how LinkedIn had stored credentials. Passwords were hashed with SHA-1 but without salting, a basic technique that makes each stored hash unique. Without it, attackers could crack large portions of the dataset quickly using precomputed tables and commodity hardware, and researchers reported that the overwhelming majority of the passwords were recovered within days. That turned an old breach into a live threat, because many users had reused the same password on email, banking and other services.
LinkedIn acknowledged that the 2016 data came from the 2012 intrusion, invalidated passwords for affected accounts that had not been changed since then, and urged users to enable two-step verification. The company had moved to salted hashing after the original incident. The episode was part of a wave of so-called mega-breach dumps in 2016, as older troves from MySpace, Tumblr and VK surfaced through the same seller around the same period.
The case also produced a rare criminal prosecution. Czech police arrested Russian national Yevgeniy Nikulin in Prague in October 2016 at the request of US authorities, who accused him of hacking LinkedIn, Dropbox and Formspring. He was extradited to the United States in 2018, convicted by a federal jury in San Francisco in 2020, and sentenced to 88 months in prison. Separately, LinkedIn had earlier agreed to a $1.25 million class action settlement with premium subscribers over its password security.
The LinkedIn breach remains one of the clearest demonstrations of why credential storage matters. Weak hashing converted a contained incident into years of credential-stuffing risk across the internet. It helped popularize breach-notification services such as Have I Been Pwned and reinforced advice that users should never reuse passwords and should adopt password managers and multi-factor authentication.