117M LinkedIn user emails and passwords from 2012 hack offered for sale on dark web marketplace; LinkedIn is contacting affected users
A LinkedIn hack from back in 2012 is still causing problems for its users. The company announced this morning that another data set from the hack …
Context & Ripple Effects
Four years after LinkedIn's 2012 breach, a dataset of 117M emails and passwords has surfaced on a dark web marketplace — far larger than the ~6.5M hashes originally disclosed at the time — and LinkedIn is now contacting affected users directly. The seller behind the dump quickly claimed to hold more: within days he was advertising a 360M-record Myspace email database, signaling a broker working through multiple old breaches rather than a one-off leak.
The sale also feeds forward technically: security researchers warned that a full plaintext dump of LinkedIn passwords will accelerate cracking of hashed passwords from any future breach, since reused passwords let attackers test known patterns against new hash sets (the full-dump cracking effect). And it foreshadows LinkedIn's recurring data problem — by 2021, separate sellers were offering 500M scraped user profiles and then 700M records mixing site data with other sources.
First-order effects
- LinkedIn must notify and force resets for up to 117M account holders whose 2012-era credentials are now tradeable, while those users face immediate credential-stuffing risk on any other site where they reused the same password.
- Buyers of the dump gain a validated email-password corpus for automated login attempts across major consumer services, not just LinkedIn.
Second-order effects
- The same seller's claimed 360M Myspace database shows old-breach inventory being monetized platform by platform, pressuring other pre-2016 services to audit and proactively reset legacy credentials before their dumps surface.
- Because the plaintext dump trains cracking tools, every subsequent hashed breach becomes cheaper to attack — raising the effective cost of weak hashing and slow disclosure for all companies holding password databases.
Third-order effects
- If breaches from a decade ago keep generating sellable inventory, breach liability effectively never expires, pushing platforms toward continuous re-verification of aged credentials rather than one-time incident response.
- The 2012 dump and the 2021 scraped-profile sales together frame LinkedIn user data as a durable commodity — both stolen credentials and legitimately public profile fields end up on the same marketplaces, blurring the line between hacking and scraping that regulators are only beginning to address.
The trend: Old breaches are becoming long-lived commodities: credentials and profile data stay monetizable on dark web markets for years after the original incident, forcing platforms to treat past hacks as ongoing liabilities rather than closed events.