Have I Been Pwned adds almost 71M email addresses tied to stolen accounts from the Naz.API dataset, which allegedly contains 1B+ lines of stolen credentials
Have I Been Pwned has added almost 71 million email addresses associated with stolen accounts in the Naz.API dataset to its data breach notification service.
Context & Ripple Effects
Have I Been Pwned has steadily expanded from a password-checking service into infrastructure for distributing compromise intelligence: its Pwned Passwords API enabled safer credential checks, while later law-enforcement sharing of compromised passwords broadened the supply of data it can surface. The Naz.API addition extends that same model to a large alleged credential corpus.
The significance is not proof of a newly disclosed breach at a single company; it is the conversion of a circulating collection of stolen-account data into a lookup signal that people and security teams can act on.
First-order effects
- Nearly 71 million email-address holders can now learn whether their address appears in the Naz.API material through Have I Been Pwned’s breach-notification service.
- Organizations and password managers using compromise checks gain another source for identifying accounts that may require password resets or stronger account review.
Second-order effects
- Security teams will face more pressure to treat reused or previously exposed credentials as an ongoing account-takeover risk, rather than a response limited to a named company breach.
- The value of HIBP’s distribution layer rises as more compromised-data sources—including the earlier open-sourced Pwned Passwords effort—are made usable in defensive workflows.
Third-order effects
- If large credential compilations continue to be operationalized this way, identity security will shift further toward continuous credential screening and remediation rather than one-off breach notices.
- The limiting question will increasingly be data provenance and responsible handling: defenders need actionable indicators without treating every claimed credential collection as equally reliable.
The trend: This is part of the shift from breach-by-breach disclosure toward continuous, shared compromised-credential intelligence for account security.