117M LinkedIn user emails and passwords from 2012 hack offered for sale on dark web marketplace; LinkedIn is contacting affected users
LinkedIn.com was hacked in June 2012 and a copy … Brian Krebs / Sydney Morning Herald : LinkedIn breach affected more than 100 million users, site confirms MacNN : LinkedIn breach of 2012 found to be far greater than first thought Lorenzo Franceschi-Bicchierai / Motherboard : Another Day, Another Hack: 117 Million LinkedIn Emails And Passwords Mariella Moon / Engadget : Millions of LinkedIn passwords stolen in 2012 surface online Lisa Vaas / Naked Security : Millions of LinkedIn passwords up for sale on the dark web Gautham / NEWSBTC : Hacker Sells LinkedIn Users' Data for Bitcoin Catalin Cimpanu / Softpedia News : Top Passwords from the LinkedIn Data Breach Brian Krebs / Krebs on Security : As Scope of 2012 Breach Expands, LinkedIn to Again Reset Passwords for Some Users Daniel Victor / New York Times : LinkedIn Says Hackers Are Trying to Sell Fruits of Huge 2012 Data Breach Mohit Kumar / The Hacker News : Hacker puts up 167 Million LinkedIn Passwords for Sale Andrew Hutchinson / Social Media Today : MORE THAN 117 MILLION LINKEDIN ACCOUNTS CAUGHT UP IN DATA BREACH Matthew Zeitlin / BuzzFeed : LinkedIn Says Hackers May Have Stolen More Than 100 Million Passwords Sean Michael Kerner / eWeek : LinkedIn's 2012 Breach Still Puts Users at Risk Thomas Fox-Brewster / Forbes : LinkedIn Resets Passwords As 117M Logins For Sale On Dark Web - UPDATED Alyssa Newcomb / ABC News : LinkedIn Data Breach From 2012 Comes Back to Haunt Users Robert Pleasant / SiliconANGLE : Old LinkedIn data breach resurfaces with 167 million accounts at risk Brad Jones / Digital Trends : Report: Hacker puts data from 167 million LinkedIn accounts up for sale Olivia Harrison / Refinery29 : 117 Million Hacked LinkedIn Accounts Are Being Sold On The Dark Web Robert Hackett / Fortune : Here Are the Most Common Passwords Found in the Hacked LinkedIn Data Steven Loeb / VatorNews : A four year-old data breach is back to haunt LinkedIn Bob Sullivan / GeekWire : LinkedIn's huge password leak even bigger than originally thought Blake Neff / The Daily Caller : If You Have A LinkedIn Account, You Should Probably Change Your Password Right Now Chris Scott Barr / SlashGear : 2012 Linkedin hack is back to haunt 117 million users Kevin Townsend / SecurityWeek : Scrub 6.5 Million - It Was 117 Million Passwords Stolen From LinkedIn in 2012 Shawn Knight / TechSpot : 167 million LinkedIn accounts for sale on dark market, linked to 2012 breach Paul Sawers / VentureBeat : LinkedIn resets passwords on millions of accounts as new data-leak reports surface Ian Barker / BetaNews : Four-year-old LinkedIn IDs go up for sale online Dan Goodin / Ars Technica UK : Then there were 117 million. LinkedIn password breach much bigger than thought Nathan McAlone / Tech Insider : A hacker is reportedly selling the stolen emails and passwords of 117 million LinkedIn users (LNKD) Alexis Shaw / AOL : A hacker is reportedly selling the stolen emails and passwords of 117 million LinkedIn users David Cohen / SocialTimes : 2012 LinkedIn Security Breach Strikes Again Office of Inadequate Security : 117 Million LinkedIn Emails And Passwords up for sale (Updated) Pierluigi Paganini / Security Affairs : 117 Million LinkedIn credentials offered for sale Daniel White / TIME : Linkedin Is Asking Millions of People to Change Their Passwords
Context & Ripple Effects
The 2012 LinkedIn breach was long assumed to be around 6.5 million compromised accounts; this week a copy with 117 million email-and-password pairs surfaced on a dark web marketplace, forcing LinkedIn into retroactive incident response — contacting users and resetting passwords four years after the fact. The seller is the same actor who days later claimed to hold 360 million Myspace user emails with passwords, suggesting a business model built on reselling caches of old mega-breaches.
The story also has a technical tail: security researchers note that a full dump of unsalted LinkedIn hashes gives attackers a massive precomputed corpus, an analysis of how the full dump will speed cracking of hashed passwords in any future breach. And it foreshadows LinkedIn's recurring data problem — by 2021 the company was dealing with a scraped dataset of 500M users posted for sale, then another covering 700M.
First-order effects
- LinkedIn must notify and force password resets for up to 117 million users whose 2012-era credentials are now tradeable, while those users face immediate credential-stuffing risk on any site where they reused the same password.
- Buyers on the dark web gain a verified, large-scale email-password corpus priced in Bitcoin, turning a four-year-old breach into fresh attack inventory.
Second-order effects
- The same hacker's claimed 360M-record Myspace cache signals that other legacy breaches are being monetized in sequence, pressuring every major consumer platform of that era to audit its own 2011-2013 breach disclosures.
- Because the dump includes crackable unsalted hashes, defenders everywhere face faster password-guessing against future breaches, raising the effective cost of weak hashing schemes across the industry.
Third-order effects
- Breach response is decoupling from breach time: companies can be forced into user notification and remediation years after an intrusion, making long-tail data retention and hashing choices a standing liability rather than a one-time incident.
- If resale of aged breach corpora becomes routine, the market for stolen credentials matures into a durable commodity trade — pushing platforms toward breach-proofing measures like salted/adaptive hashing and pushing regulators toward longer accountability windows for historical incidents.
The trend: Old mega-breach databases are resurfacing as dark web commodities years later, converting stale security failures into present-day liability for the platforms involved.