Security researcher publishes 10M unredacted usernames with passwords despite risk of FBI raid
Fearing an FBI raid, researcher publishes 10 million passwords/usernames — Move could advance password research—and test prosecutors' tolerance for leaks.
Context & Ripple Effects
This 2015 leak sits at the start of a decade-long fight over who is allowed to hold breach data. The researcher's gamble — publish 10M unredacted username/password pairs before investigators could seize them — directly anticipated what happened to commercial holders of the same material: LeakedSource was taken offline after an alleged police raid in 2017, and the FBI seized WeLeakInfo's domain in 2020 over its 12B-credential trove.
The resolution the researcher never had came later, from the other direction: by 2021 [[a:966805|Have I Been Pwned went open source and began receiving compromised passwords straight from FBI investigations]], making a single vetted repository the sanctioned channel for exactly the kind of data this leak dumped into the open.
First-order effects
- US prosecutors face the test the headline names: decide whether publishing unredacted credentials for research counts as disclosure or as trafficking in hacked data — the same distinction that later justified action against LeakedSource and WeLeakInfo.
- Account holders whose plaintext credentials are now public must rotate them immediately; any service those passwords unlock inherits a live credential-stuffing exposure.
Second-order effects
- Commercial breach-data sellers lose the 'researcher precedent' defense — enforcement against LeakedSource and WeLeakInfo shows the tolerated line runs through vetted security services, not paid lookup sites.
- Legitimate password-checking services gain both raw data and a cautionary tale, pushing the field toward curated, hashed corpora rather than raw dumps.
Third-order effects
- If the pattern holds, breach-data handling consolidates around state-connected intermediaries like Have I Been Pwned while independent holders face seizure risk — the state choosing which custodians of leaked credentials exist at all.
- Researchers' self-censorship under raid risk narrows the evidence base for password research, leaving official channels as the de facto gatekeepers of what the field can study.
The trend: Breach-data custody is shifting from gray-zone researcher dumps and commercial lookup sites toward a single state-vetted pipeline, with FBI seizures drawing the boundary.