How the full dump of LinkedIn passwords from 2012 hack will speed cracking of hashed passwords from any future breaches
Second data dump lets hackers be 6 times better cracking future dumps. … Me: “The full dump from the 2012 LinkedIn breach just dropped, so you're probably not going to see much of me over the next week.” Tweets: @tinolle , @alexcryptan , @dannynemer , @tadegbesan and @joshconstine Tweets: Milos Constantin / @tinolle : 180 million passwords, 98% cracked in one week. #LinkedIn ** http://arstechnica.com/... http://twitter.com/..." Alex Biryukov / @alexcryptan : LinkedIn used unsalted SHA-1 for password storage in 2012. 180 million passwords, 98% cracked in one week. http://goo.gl/HtAuLW Danny Nemer / @dannynemer : Password breaches of a few services endangers all via statistical data improving brute force http://arstechnica.com/... pic.twitter.com/CjCBuMRpD1 Tunji Adegbesan / @tadegbesan : “Using a single Sagitta HPC Brutalis wit 8 Nvidia GTX Titan X cards I managed2 recover 85% of passwords the 1st day” http://arstechnica.com/... Josh Constine / @joshconstine : Thx, LinkedIn. Such lazy security let its passwords be cracked, giving hackers a cheat sheet for future breaches http://arstechnica.com/...
Context & Ripple Effects
The full dump lands weeks after 117M LinkedIn email-and-password pairs from the same 2012 breach were offered for sale on a dark web marketplace, prompting LinkedIn to contact affected users. What changed now is scale and completeness: the new release exposes roughly 180 million passwords, and because LinkedIn stored them as unsalted SHA-1, cryptographer Alex Biryukov reports 98% were cracked within a week.
The timing matters for the rest of the breach economy. The same seller behind the LinkedIn sale claims to hold 360M Myspace user emails with passwords, so every additional cracked plaintext from LinkedIn feeds directly into attacks on users who reused credentials across those services.
First-order effects
- LinkedIn users whose 2012 passwords are now effectively public face immediate account-takeover risk wherever they reused those credentials, and defenders lose the obscurity that partial leaks previously provided.
- Attackers gain a verified training set of ~180 million real password choices, reported to make cracking of hashed passwords in future breaches up to ~6x more effective.
Second-order effects
- Any service whose users overlapped with LinkedIn — starting with the Myspace trove already claimed for sale — becomes cheaper to attack, since cracked LinkedIn plaintexts double as candidate passwords elsewhere.
- Password-cracking economics shift toward GPU rigs like the GTX Titan X setups named in the coverage, making hardware investment in cracking more attractive as each new dump raises its yield.
Third-order effects
- Old breaches stop expiring: hashed corpora accumulate into permanent cracking dictionaries, a pattern the 2019 distribution of Collections #2-5 — 25 billion records — shows compounding at scale.
- If legacy hashing schemes keep failing this way, the structural pressure moves toward salted, slow hashing and multi-factor authentication as baseline requirements rather than options, since password secrecy alone can no longer be assumed durable.
The trend: Breach data is becoming a compounding asset — each dumped password corpus makes the next breach faster to crack, steadily eroding the password as a standalone defense.