Profile of Alex Holden, who tracked down the Russian hackers who stole over 1.2B credentials
Meet The Man Who Finds Your Stolen Passwords — Last summer a gang of Russian hackers was caught amassing the largest cache of stolen user names and passwords ever discovered—1.2 billion in all.
Context & Ripple Effects
This 2015 profile lands at the start of the credential-theft escalation the later coverage documents: Alex Holden's tracking of the gang behind a record 1.2-billion-credential cache was the moment bulk stolen logins became a measurable market rather than isolated breach fallout. Within a year of the piece, a security expert counted 272.3 million email credentials being traded in the Russian underworld — 57M Mail.ru, 40M Yahoo, 33M Hotmail, 24M Gmail — showing Holden had surfaced the supply side of a trade that kept compounding.
Why it matters: the same coverage trail shows both halves of what Holden's kind of work enables — the criminal side (Collections #2-5 nearly tripled Collection #1 at 25B records by 2019) and the accountability side, with a Russian man arrested in the Czech Republic over LinkedIn's 117M-password breach and later a Ukrainian Secret Service arrest of a hacker accused of selling billions of credentials. The profile captures the researcher-attribution layer that those eventual arrests depend on.
First-order effects
- Holden's identification of the Russian gang gives breached companies and law enforcement actionable attribution on a 1.2B-credential haul, forcing affected services to reset compromised accounts immediately.
Second-order effects
- Once caches this large surface, they feed the resale pipeline documented in the related coverage — underworld brokers packaging Mail.ru, Yahoo, Hotmail, and Gmail credentials for buyers, which pressures email providers into detection and forced-password-change cycles.
Third-order effects
- If the pattern holds, credential theft industrializes into bulk commodity trading (Collections-style dumps), while researcher forensics plus cross-border arrests — Czech Republic, Ukraine — become the standing counter-model, and chronic password reuse keeps each new dump dangerous long after the original breach.
The trend: Stolen-credential theft is scaling from single mega-caches into a commoditized underground resale market, with independent researchers' attribution work feeding the slow, cross-border enforcement response.