Nearly 10 Billion Passwords Leaked in Biggest Compilation of All Time (2024)

The world’s largest compilation of passwords to be leaked online has been discovered by a research team at Cybernews, containing 9,948,575,739 unique plaintext entries. The credentials were discovered in a file named “rockyou2024.txt” that was posted on a popular hacking forum on July 4, 2024.

Many of the so-called RockYou2024 passwords have already been leaked in previous data breaches. This is not the first RockYou data dump either, as the name has been associated with a number of large-scale password leaks since 2009.

The user who posted RockYou2024, who has the username “ObamaCare,” has been responsible for multiple data dumps since creating their account in May 2024. They have shared an employee database from law firm Simmons & Simmons, a lead from online casino AskGamblers and student applications for Rowan College at Burlington County in New Jersey.

RockYou is a defunct social application site and, in 2009, more than 32 million of its users’ account details were exposed after a hacker got hold of the plaintext file where they had been stored. In June 2021, another text file was posted named “rockyou2021.txt.” This 100GB file contained 8.4 billion passwords, making it the largest ever password dump at the time.

How this password leak heightens the risk of credential stuffing attacks

The Cybernews team believes that RockYou2024 has all the passwords from RockYou2021, plus another 1.5 billion new passwords. In total, the file contains information from more than 4,000 databases.

“In its essence, the RockYou2024 leak is a compilation of real-world passwords used by individuals all over the world,” researchers said. “Revealing that many passwords for threat actors substantially heightens the risk of credential stuffing attacks.”

Credential stuffing attacks, where attackers use automated tools to try stolen username-password pairs on different websites to test if credentials have been reused, are relatively common.

DOWNLOAD: Best Practices for Password Creation and Storage from TechRepublic Premium

In June 2024, a threat actor managed to access the Snowflake cloud data platform through a successful credential stuffing attack and was able to extract data from 165 of their clients.

In November 2023, hackers were able to steal the personal and genetic information of 6.9 million people from 23andMe after leveraging stolen account sessions and legitimate login credentials. The company blamed its users for the breach, saying they “negligently recycled” their details in a letter acquired by TechCrunch.

RockYou2024 could offer threat actors a new source of passwords to try in credential stuffing attacks to help them gain unauthorised access to individuals’ online accounts. These accounts could be for online and offline services, IoT cameras and industrial hardware.

“Combined with other leaked databases on hacker forums and marketplaces, which, for example, contain user email addresses and other credentials, RockYou2024 can contribute to a cascade of data breaches, financial frauds, and identity thefts,” the Cybenews team said.

Advice for mitigating the risk of credential stuffing attacks

Jake Moore, global cybersecurity advisor at security firm ESET, told TechRepublic: “User credentials are constantly being caught up in data breaches and they end up being collected and stored in large databases on the dark web.

“Therefore, these days there is no excuse for not using a unique password for every account – especially as data breaches continue to increase. Criminals can exploit known credentials across multiple accounts and many people using the same password across different sites are at risk of being compromised.

“Fortunately, passphrases and password managers are now easier to use and integrate into daily life. They handle the difficult task of generating and securely storing complex passwords and other codes so we don’t have to remember them. Additionally, combining this with multi-factor authentication for all accounts enhances security and helps better protect people’s accounts.”

SEE: 8 Best Enterprise Password Managers for 2024

Tips for anyone impacted by the RockYou2024 breach

The Cybernews researchers have made a number of recommendations for the individuals and organisations impacted by the RockYou2024 breach. These are:

  1. Immediately reset all passwords that appeared in the data breach. Ideally, new passwords should be strong and unique to their account.
  2. Enable multi-factor authentication.
  3. Utilise password manager software that generates and stores complex passwords that are unique to each account.

Subscribe to the Cybersecurity Insider Newsletter

Strengthen your organization's IT security defenses by keeping abreast of the latest cybersecurity news, solutions, and best practices. Delivered every Monday, Tuesday and Thursday

Subscribe to the Cybersecurity Insider Newsletter

Strengthen your organization's IT security defenses by keeping abreast of the latest cybersecurity news, solutions, and best practices. Delivered every Monday, Tuesday and Thursday

Nearly 10 Billion Passwords Leaked in Biggest Compilation of All Time (2024)

FAQs

Nearly 10 Billion Passwords Leaked in Biggest Compilation of All Time? ›

Researchers discovered the file named RockYou2024 posted by user “ObamaCare” on July 4 with 9,948,575,739 unique plaintext passwords. “The Cybernews team believes that attackers can utilize the ten-billion-strong RockYou2024 compilation to target any system that isn't protected against brute-force attacks.

What was the biggest password leak? ›

Researchers at Cybernews said they discovered the file, posted on July 4, with 9,948,575,739 unique plaintext passwords. Cybernews experts said they believe this data dump, called RockYou2024, is the largest password leak of all time.

What does it mean when iPhone says your password appeared in data leak? ›

For example, if your password for your Amazon account is “redsox2004”, and your iPhone informs you it has appeared in a data leak, this simply means that in publicly available account credentials covering various companies that were breached, “redsox2004” was on the list of passwords.

What is RockYou 2024? ›

July 8, 2024. 1 Min Read. Source: designer491 via Alamy Stock Photo. A user has leaked nearly 10 billion unique plaintext passwords on a popular hacking forum, seemingly obtained through several past breaches. The list is coined RockYou2024, due to its file name, rockyou.txt.

How does Apple know my password is compromised? ›

Your iPhone checks your usernames and passwords against information reported in data breach reports from the sites you have visited. These are not Apple data leaks, they are data leaks from businesses that you have accounts with.

What is the number 1 used password? ›

Almost four decades since the advent of the internet, you'll be surprised that people still choose convenience over security. According to a study by NordPass, the most commonly used passwords include “123456”, “123456789”, “qwerty”, “password”, and “111111”.

What's the worst password? ›

National Cyber Security Centre
Rank2019
1123456
2123456789
3qwerty
4password
16 more rows

Should I be worried about Apple password data leak? ›

Yes, you should be concerned about leaked passwords. A compromised password means unauthorized individuals can access your personal information and accounts.

Should I delete or change compromised passwords? ›

Compromised passwords and username combinations are unsafe because they've been published online. We recommend that you change any compromised passwords as soon as you can.

Should I change my password if it was in a data leak? ›

The notice informs you that your login credentials have been compromised during a cyberattack or your password is leaked in a data breach. The usual recommendation is that you should immediately change your account password.

How many passwords does RockYou contain? ›

The name "RockYou2024" pays homage to the infamous RockYou data breach of 2009, which exposed 32 million passwords due to insecure storage practices.

How was RockYou hacked? ›

In December 2009, RockYou experienced a data breach resulting in the exposure of over 32 million user accounts. This resulted from storing user data in an unencrypted database (including user passwords in plain text instead of using a cryptographic hash) and not patching a ten-year-old SQL vulnerability.

Where is Kali wordlist located? ›

Kali Linux includes several word lists in the /usr/share/wordlists/ directory.

Does Apple warn you if your phone is being hacked? ›

Additionally, Apple will send an email and iMessage notification to the phone number and email address associated with the user's Apple ID. Each of these threat notifications will explain additional steps that the user can take to protect their devices.

What Apple devices are at risk of being hacked? ›

iPhone XS and later, iPad Pro 12.9-inch 2nd generation and later, iPad Pro 10.5-inch, iPad Pro 11-inch 1st generation and later, iPad Air 3rd generation and later, iPad 6th generation and later, and iPad mini 5th generation and later. Apple Safari versions prior to 17.3. macOS Monterey and macOS Ventura.

How can you tell if someone is logged into your Apple ID? ›

From the Devices section of your Apple ID account page, you can find all of the devices that you're currently signed in to with your Apple ID, including Android devices, consoles, and smart TVs: Sign in to appleid.apple.com,* then select Devices.

What is the most famous data leak? ›

26 Biggest Data Breaches in US History
  1. 1. Yahoo! Date: 2013-2016. ...
  2. Microsoft. Date: January 2021. ...
  3. Real Estate Wealth Network. Date: December 2023. ...
  4. First American Financial Corp. Date: May 2019. ...
  5. 5. Facebook. Date: April 2021. ...
  6. LinkedIn. Date: April 2021. ...
  7. JPMorgan Chase. Date: June 2014. ...
  8. Home Depot. Date: April 2014.

What is the strongest password ever? ›

The best, most powerful and strongest passwords are long, hard-to-guess, and unique. That means using a minimum of 15 characters, using words or phrases that are hard to guess and difficult to connect to you, and never reusing passwords across multiple accounts.

What is the most common hacked password? ›

Most hackable passwords

Second came “123456” followed by the slightly longer “123456789.” Rounding out the top five were “guest” and “qwerty.” Most of those log-ins can be cracked in less than a second.

What is the most unbreakable password? ›

A 32-character password has the potential to be much stronger than an 8-character password. The key is to find a password that you find memorable. Use a unique phrase or combination of words that a hacker wouldn't know. This is the best way to keep yourself safe from network security risks.

References

Top Articles
Latest Posts
Article information

Author: Trent Wehner

Last Updated:

Views: 5868

Rating: 4.6 / 5 (56 voted)

Reviews: 87% of readers found this page helpful

Author information

Name: Trent Wehner

Birthday: 1993-03-14

Address: 872 Kevin Squares, New Codyville, AK 01785-0416

Phone: +18698800304764

Job: Senior Farming Developer

Hobby: Paintball, Calligraphy, Hunting, Flying disc, Lapidary, Rafting, Inline skating

Introduction: My name is Trent Wehner, I am a talented, brainy, zealous, light, funny, gleaming, attractive person who loves writing and wants to share my knowledge and understanding with you.