Security expert says 272.3M email credentials being traded in Russian underworld: 57M Mail.ru, 40M Yahoo, 33M Hotmail, and 24M Gmail
Exclusive: Big data breaches found at major email services - expert — Hundreds of millions of hacked usernames and passwords for email accounts …
Context & Ripple Effects
The Reuters exclusive put a price tag on years of quiet breaches: a security expert found 272.3M email credentials — 57M Mail.ru, 40M Yahoo, 33M Hotmail, 24M Gmail — actively traded in the Russian underworld rather than sitting in an unmonitored dump. Within days, Mail.ru and Google publicly claimed over 98% of the listed credentials were invalid on their services, a defensive disclosure that reframed the story from fresh compromise to stale-password inventory (providers said most credentials were already dead).
The episode landed months before Yahoo confirmed data from 500M+ accounts was stolen in 2014 by what it called a state-sponsored actor, including hashed passwords and security questions — evidence that the mega-breach era at major webmail providers was real, not underworld rumor.
First-order effects
- Mail.ru, Google, Microsoft and Yahoo are pushed into immediate credential hygiene: forcing resets, flagging reused passwords, and publicly discounting the dump's validity to contain user panic.
- Users whose credentials appear in the stash face direct account-takeover attempts wherever they reused those passwords beyond webmail.
Second-order effects
- Credential-stuffing pressure shifts downstream to every service that authenticates with an email-and-password pair, since even mostly-invalid dumps leave millions of live pairs for attackers to test elsewhere.
- Rival providers must match the disclosure playbook — quantifying how much of a dump is stale becomes the standard PR defense, as Mail.ru and Google demonstrated within days of publication.
Third-order effects
- If mega-dumps keep surfacing — from this stash to the Rambler.ru leak of 98M records with plaintext passwords to Yahoo's confirmed theft of 500M+ account records — password reuse stops being a user error and becomes a systemic design problem, accelerating industry movement toward multi-factor authentication and breach-notification obligations.
- Email providers' security posture turns into a competitive differentiator, since every subsequent dump forces them to re-litigate trust in front of users and regulators alike.
The trend: Webmail is moving from per-account breach incidents to an era of industrial-scale credential markets, where providers compete on how fast they can invalidate and re-secure hundreds of millions of leaked logins.