Following highly publicized report of 272M email credentials for sale in Russia, Mail.ru and Google both say 98%+ of credentials on their services are invalid
Garbage in, garbage out: Why Ars ignored this week's massive password breach — When a script kiddie sells 272 million accounts for $1, be very, very skeptical.
Context & Ripple Effects
Three days after [[a:869092|a security researcher tallied 272.3 million email credentials circulating in the Russian underworld]] — 57M Mail.ru, 40M Yahoo, 33M Hotmail, 24M Gmail — the two biggest named providers have pushed back hard: both say more than 98% of the combinations touching their services don't actually work. That tracks with the pattern Alex Holden documented when he traced over 1.2 billion stolen credentials held by Russian hacking groups: underworld caches are heavy on recycled, long-expired data.
Ars' own framing — ignoring the story rather than amplifying it — is the analytical point. The episode tests how breach reporting should handle bulk credential sales where freshness can't be verified, a question that recurs whether the data surfaces on an underground forum or on a commercial leak-search site.
First-order effects
- Mail.ru and Google shift the burden of proof onto the sellers: by publishing their own validation rates, they turn an alarming headline into a claim about stale data, not a confirmed compromise of their systems.
Second-order effects
- Credential brokers selling bundles for token prices — this batch reportedly listed at $1 — are effectively dumping inventory whose value lies in reuse against other services, keeping recycled combinations in circulation even after the original providers invalidate them.
Third-order effects
- If the pattern holds, breach coverage and any downstream regulatory attention will hinge on provider-side validation rather than raw record counts, and the line between 'new hack' and 'repackaged old dump' becomes the central question for every future mega-leak headline.
The trend: Stolen-credential markets increasingly trade in recycled and largely invalid data, pushing email providers into the role of de facto verifiers of breach claims.