Skip to main content
Back
Exploit.In

Exploit.In

Exploit.In

criticalHave I Been Pwned

#24 largest data breach on record

Disclosed

October 13, 2016

3452 days ago

Records

593.4M

Estimated

Root Cause

Credential Stuffing

Industry

Unknown

Description

In late 2016, a huge list of email address and password pairs appeared in a "combo list" referred to as "Exploit.In". The list contained 593 million unique email addresses, many with multiple different passwords hacked from various online systems. The list was broadly circulated and used for "credential stuffing", that is attackers employ it in an attempt to identify other online systems where the account owner had reused their password. For detailed background on this incident, read Password reuse, credential stuffing and another billion records in Have I Been Pwned.

View source
Exposed Data Types

Exposed Data

PasswordsEmail Addresses
Exploit.In Data Breach (2016) - 593.4M Records | ExposedMap