The UK National Crime Agency (NCA) has discovered a database containing more than 585 million stolen passwords and emails, and shared it with Have I Been Pwned? to expand and update its database of breached info.
According to the report, the NCA found the database in a “compromised cloud storage facility”:
“During recent NCA operational activity, the NCCU’s Mitigation@Scale team were able to identify a huge amount of potentially compromised credentials (emails and associated passwords) in a compromised cloud storage facility. Through analysis, it became clear that these credentials were an accumulation of breached datasets known and unknown,” the organization’s announcement reads.
“The fact that they had been placed on a UK business’s cloud storage facility by unknown criminal actors meant the credentials now existed in the public domain and could be accessed by other 3rd parties to commit further fraud or cyber offenses.”
Of the 585 million passwords that were shared with HaveIBeenPwned, more than 225 million were unique - those he hasn’t seen before. With 613 million credentials already sitting in Have I Been Pwned's database, this launch now brings the total number up to around 847 million.
Creating strong passwords
Cybersecurity experts often claim passwords are one of the weakest security measures in existence, better only than having no password, at all.
Businesses, workers and individuals are advised to switch to a passwordless method, such as biometrics (fingerprint scanner, facial recognition, or similar), or to deploy multi-factor authentication, either through security keys, a 2FA app, or a token generator.
Many people still use weak and easy-to-guess passwords, risking their online identities being easily stolen.
For example, “123Tests” was one of the passwords found in the database. Passwords should always be a combination of uppercase and lowercase letters, numbers and symbols, should not represent anything easily discovered online (a date of birth, the name of a significant other, or a pet, for example), and should never be the same for multiple services. Many experts are recommending password managers as means of creating and maintaining strong passwords.
- You might also want to check out our list of the best identity management service providers out there