The Have I Been Pwned knowledge breach notification service has added over 284 million accounts stolen by info stealer malware and located on a Telegram channel.
HIBP founder Troy Hunt says he discovered 284,132,969 compromised accounts whereas analyzing 1.5TB of stealer logs possible collected from quite a few sources and shared on a Telegram channel often known as “ALIEN TXTBASE.”
“They include 23 billion rows with 493 million distinctive web site and e mail handle pairs, affecting 284M distinctive e mail addresses,” Hunt acknowledged in a Tuesday weblog.
“We have additionally added 244M passwords we have by no means seen earlier than to Pwned Passwords and up to date the counts in opposition to one other 199M that have been already in there.”
Because of the massive variety of accounts on this assortment, the information may additionally possible embrace each outdated and new credentials stolen by way of credential stuffing assaults and knowledge breaches.
Earlier than including the stolen accounts to HIBP’s database, Troy confirmed their authenticity by checking if a password reset try utilizing the stolen e mail addresses triggered the service to ship a password reset e mail.
Utilizing newly added APIs (permitting as much as 1000 e mail handle searches per minute and stealer log searchers), area homeowners and web site operators (who pay for a month-to-month subscription) can now determine prospects whose credentials have been stolen by querying the added stealer logs by e mail area or web site area.
When requested if common customers can even discover out if their accounts have been discovered within the ALIEN TXTBASE infostealer logs, Troy mentioned they might in the event that they’re additionally subscribed to HIBP notifications.
“However it’ll solely present what web sites their credentials have been captured in opposition to in the event that they use the notification service to confirm their handle, I did not need to present that data publicly as it may expose the usage of delicate providers,” he mentioned.
“The introduction of those new APIs at this time will lastly assist many organisations determine the supply of malicious exercise and much more importantly, get forward of it and block it earlier than it does harm,” he added.
In December 2021, HIBP additionally added 441,000 accounts stolen in an information-stealing marketing campaign utilizing RedLine malware, some of the extensively used infostealers on the time. The information was discovered on an unsecured server, which uncovered over 6 million RedLine logs collected in August and September 2021.
Extra not too long ago, earlier this month, HIBP added the accounts of 12 million Zacks Funding customers whose delicate knowledge (together with names, usernames, e mail addresses, IP addresses, bodily addresses, and cellphone numbers) was uncovered in a safety breach.
Two years in the past, in June 2023, the breach notification service added one other database with the e-mail addresses, usernames, unsalted SHA256 passwords, addresses, cellphone numbers, and full names of one other 8.8 million people utilizing Zacks’ platform.

