Remember the Ashley Madison data breach? That was now more than a decade ago, yet it arguably remains the single most noteworthy data breach of all time. There are many reasons for this accolade, but chief among them is that by virtue of the site being expressly designed to facilitate extramarital affairs, there was massive…
Category: Have I Been Pwned
Global Security News, Have I Been Pwned
Processing 630 Million More Pwned Passwords, Courtesy of the FBI
The sheer scope of cybercrime can be hard to fathom, even when you live and breathe it every day. It’s not just the volume of data, but also the extent to which it replicates across criminal actors seeking to abuse it for their own gain, and to our detriment. We were reminded of this recently…
Global Security News, Have I Been Pwned
Why Does Have I Been Pwned Contain “Fake” Email Addresses?
Normally, when someone sends feedback like this, I ignore it, but it happens often enough that it deserves an explainer, because the answer is really, really simple. So simple, in fact, that it should be evident to the likes of Bruce, who decided his misunderstanding deserved a 1-star Trustpilot review yesterday: Now, frankly, Trustpilot is…
Cybersecurity, data breach, Global Security News, Have I Been Pwned, HIBP, Security
Have I Been Pwned Adds 1.96B Accounts From Synthient Credential Data
Have I Been Pwned (HIBP), the popular breach notification service, has added another massive dataset to its platform.…
Global Security News, Have I Been Pwned
2 Billion Email Addresses Were Exposed, and We Indexed Them All in Have I Been Pwned
I hate hyperbolic news headlines about data breaches, but for the “2 Billion Email Addresses” headline to be hyperbolic, it’d need to be exaggerated or overstated – and it isn’t. It’s rounded up from the more precise number of 1,957,476,021 unique email addresses, but other than that, it’s exactly what it sounds like. Oh –…
Cybersecurity, Global Security News, Have I Been Pwned, HIBP, leaks, Security
183 Million Synthient Stealer Credentials Added to Have I Been Pwned
Massive Synthient Stealer Log leak adds 183 million stolen usernames and passwords to Have I Been Pwned, exposing new victims worldwide.
Global Security News, Have I Been Pwned
Inside the Synthient Threat Data
Where is your data on the internet? I mean, outside the places you’ve consciously provided it, where has it now flowed to and is being used and abused in ways you’ve never expected? The truth is that once the bad guys have your data, it often replicates over and over again via numerous channels and…
Global Security News, Have I Been Pwned
Court Injunctions are the Thoughts and Prayers of Data Breach Response
You see it all the time after a tragedy occurs somewhere, and people flock to offer their sympathies via the “thoughts and prayers” line. Sympathy is great, and we should all express that sentiment appropriately. The criticism, however, is that the line is often offered as a substitute for meaningful action. Responding to an incident…
Global Security News, Government, Have I Been Pwned
Welcoming CERN to Have I Been Pwned
It’s hard to explain the significance of CERN. It’s the birthplace of the World Wide Web and the home of the largest machine ever built, the Large Hadron Collider. The bit that’s hard to explain is, well, I mean, look at it! Charlotte and I visited CERN in 2019, nestled in there between Switzerland and…
Global Security News, Have I Been Pwned
HIBP Demo: Querying the API, and the Free Test Key!
One of the most common use cases for HIBP’s API is querying by email address, and we support hundreds of millions of searches against this endpoint every month. Loads of organisations use this service to understand the exposure of their customers and provide them with better protection against account takeover attacks. Many also use it…
Global Security News, Have I Been Pwned
Have I Been Pwned Demos Are Now Live!
Well, one of them is, but what’s important is that we now have a platform on which we can start pushing out a lot more. It’s not that HIBP is a particularly complex system that needs explaining in any depth, but we still get a lot of “how do I…” style questions for the fundamentals.…
Global Security News, Have I Been Pwned
Get Pwned, Get Local Advice From a Trusted Gov Source
We were recently travelling to faraway lands, doing meet and greets with gov partners, when one of them posed an interesting idea: What if people from our part of the world could see a link through to our local resource on data breaches provided by the gov? Initially, I was sceptical, primarily because no matter…
Global Security News, Have I Been Pwned
Welcoming Guardio to Have I Been Pwned’s Partner Program
I’m often asked if cyber criminals are getting better at impersonating legitimate organisations in order to sneak their phishing attacks through. Yes, they absolutely are, but I also argue that the inverse is true too: legitimate organisations frequently communicate in ways that are indistinguishable from a phishing attack! I can name countless examples of banks,…
Global Security News, Have I Been Pwned
Good Riddance Teespring, Hello Fourthwall
If I’m honest, I was never that keen on a merch store for Have I Been Pwned. It doesn’t make the code run faster, nor does it load any more data breaches or add any useful features to the service whatsoever. But… people were keen. They wanted swag they could wear or drink from or…
Global Security News, Have I Been Pwned
Welcoming Aura to Have I Been Pwned’s Partner Program
One of the greatest fears we all have in the wake of a data breach is having our identity stolen. Nefarious parties gather our personal information exposed in the breach, approach financial institutions and then impersonate us to do stuff like this: So I recently somewhat had my identity stolen, someone used my driver’s license…
Exploits, Global Security News, Have I Been Pwned
Welcoming Push Security to Have I Been Pwned’s Partner Program
As we gradually roll out HIBP’s Partner Program, we’re aiming to deliver targeted solutions that bridge the gap between being at risk and being protected. HIBP is the perfect place to bring these solutions to the forefront, as it’s often the point at which individuals and organisations first learn of their exposure in data breaches.…
Global Security News, Have I Been Pwned
Welcoming Truyu to Have I Been Pwned’s Partner Program
I always used to joke that when people used Have I Been Pwned (HIBP), we effectively said “Oh no – you’ve been pwned! Uh, good luck!” and left it at that. That was fine when it was a pet project used by people who live in a similar world to me, but it didn’t do…
Global Security News, Have I Been Pwned
Have I Been Pwned 2.0 is Now Live!
This has been a very long time coming, but finally, after a marathon effort, the brand new Have I Been Pwned website is now live! Feb last year is when I made the first commit to the public repo for the rebranded service, and we soft-launched the new brand in March of this year. Over…
Global Security News, Have I Been Pwned
After the Breach: Finding new Partners with Solutions for Have I Been Pwned Users
For many years, people would come to Have I Been Pwned (HIBP), run a search on their email address, get the big red “Oh no – pwned!” response and then… I’m not sure. We really didn’t have much guidance until we partnered with 1Password and started giving specific advice about how to secure your digital…
Europe, Global Security News, Have I Been Pwned
The Have I Been Pwned Alpine Grand Tour
I love a good road trip. Always have, but particularly during COVID when international options were somewhat limited, one road trip ended up, well, “extensive”. I also love the recent trips Charlotte and I have taken to spend time with many of the great agencies we’ve worked with over the years, including the FBI, CISA,…
Global Security News, Government, Have I Been Pwned
Welcoming The Gambia National CSIRT to Have I Been Pwned
Today, we’re happy to welcome the Gambia National CSIRT to Have I Been Pwned as the 38th government to be onboarded with full and free access to their government domains. We’ve been offering this service for seven years now, and it enables national CSIRTs to gain greater visibility into the impact of data breaches on…
Global Security News, Have I Been Pwned, UX
You’ll Soon Be Able to Sign in to Have I Been Pwned (but Not Login, Log in or Log On)
How do seemingly little things manage to consume so much time?! We had a suggestion this week that instead of being able to login to the new HIBP website, you should instead be able to log in. This initially confused me because I’ve been used to logging on to things for decades: So, I went…
Cybersecurity, data breach, Exclusive, Global IT News, Global Security News, Have I Been Pwned, Security, Spyware, stalkerware
Data breach at stalkerware SpyX affects close to 2 million, including thousands of Apple users
Another consumer-grade spyware operation was hacked in June 2024, which exposed thousands of Apple Account credentials. © 2024 TechCrunch. All rights reserved. For personal use only.
Global Security News, Have I Been Pwned
Soft-Launching and Open Sourcing the Have I Been Pwned Rebrand
Designing the first logo for Have I Been Pwned was easy: I took a SQL injection pattern, wrote “have i been pwned?” after it and then, just to give it a touch of class, put a rectangle with rounded corners around it: Job done! I mean really, what more did I need for a pet…
Global Security News, Have I Been Pwned
We’re Backfilling and Cleaning Stealer Logs in Have I Been Pwned
I think I’ve finally caught my breath after dealing with those 23 billion rows of stealer logs last week. That was a bit intense, as is usually the way after any large incident goes into HIBP. But the confusing nature of stealer logs coupled with an overtly long blog post explaining them and the conflation…
Android, Apple, Exclusive, Global IT News, Global Security News, Have I Been Pwned, iPad, iPhone, Security, Spyware, stalkerware
Spyzie stalkerware is spying on thousands of Android and iPhone users
Another little-known phone monitoring outfit has quietly amassed half a million customers, whose email addresses are now in Have I Been Pwned. © 2024 TechCrunch. All rights reserved. For personal use only.
Exploits, Global Security News, Have I Been Pwned
Processing 23 Billion Rows of ALIEN TXTBASE Stealer Logs
I like to start long blog posts with a tl;dr, so here it is: We’ve ingested a corpus of 1.5TB worth of stealer logs known as “ALIEN TXTBASE” into Have I Been Pwned. They contain 23 billion rows with 493 million unique website and email address pairs, affecting 284M unique email addresses. We’ve also added…
Global Security News, Have I Been Pwned
Experimenting with Stealer Logs in Have I Been Pwned
TL;DR — Email addresses in stealer logs can now be queried in HIBP to discover which websites they’ve had credentials exposed against. Individuals can see this by verifying their address using the notification service and organisations monitoring domains can pull a list back via a new API. Nasty stuff, stealer logs. I’ve written about them and…
Global Security News, Have I Been Pwned
“Pwned”, The Book, Is Now Available for Free
Nearly four years ago now, I set out to write a book with Charlotte and RobIt was the stories behind the stories, the things that drove me to write my most important blog posts, and then the things that happened afterwards. It’s almost like a collection of meta posts, each one adding behind-the-scenes commentary that…
CloudFlare, Emerging Tech, Global Security News, Have I Been Pwned
Closer to the Edge: Hyperscaling Have I Been Pwned with Cloudflare Workers and Caching
I’ve spent more than a decade now writing about how to make Have I Been Pwned (HIBP) fast. Really fast. Fast to the extent that sometimes, it was even too fast: The response from each search was coming back so quickly that the user wasn’t sure if it was legitimately checking subsequent addresses they entered…
Exploits, Global Security News, Have I Been Pwned
Inside the DemandScience by Pure Incubation Data Breach
Apparently, before a child reaches the age of 13, advertisers will have gathered more 72 million data points on them. I knew I’d seen a metric about this sometime recently, so I went looking for “7,000”, which perfectly illustrates how unaware we are of the extent of data collection on all of us. I started…
