/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

“Collection #1” database, which claims to contain records of ~773M unique email addresses and 21M passwords, some of them hashed, shows up on the web

THERE ARE BREACHES, and there are megabreaches, and there's Equifax.  But a newly revealed trove of leaked data tops …

Wired Brian Barrett

Context & Ripple Effects

The appearance of Collection #1 on the open web marks the moment credential dumps stopped being single-breach artifacts and became aggregations: ~773M unique email addresses and 21M passwords, some still hashed, compiled from many sources rather than one hack. Within two weeks, hackers were distributing Collections #2-5 — 845GB and 25B records, nearly tripling the original trove — on forums and torrents.

The pattern that follows is what makes this story structural rather than episodic: researchers later found an unprotected email-validation company database holding 763M plaintext addresses, showing that the brokers who aggregate contact data are themselves becoming breach sources, and by 2021 analysts were cataloging a 3.28B-password dump including government credentials. Collection #1 was the first widely noticed installment of that compounding pipeline.

First-order effects

  • Anyone whose address appears in the trove faces immediate credential-stuffing risk on every site where they reused a password, forcing mass password resets and a surge in breach-notification lookups.

Second-order effects

  • Email-validation and marketing-data firms — the same category as the company later caught exposing 763M plaintext addresses — come under pressure to secure or prune their aggregation pipelines, since their databases now function as breach multipliers.

Third-order effects

  • If aggregation keeps outpacing remediation, password-based authentication gives way structurally to breach-resistant alternatives, and regulators treat bulk contact-data hoarding by brokers the way they treated the credit bureaus after Equifax's 150M-record breach.

The trend: Credential leakage is shifting from isolated breaches to self-compounding mega-aggregates, with data brokers and validation firms emerging as the next systemic weak point.