“Collection #1” database, which claims to contain records of ~773M unique email addresses and 21M passwords, some of them hashed, shows up on the web
here's how to check if yours was one of them Sami Khan / International Business Times : Hackers dump 772 million email IDs online for anyone to take: What should you do? Jeff Stone / CyberScoop : Nearly 773 million email addresses leaked, spelling trouble for people who re-use passwords Ben Lovejoy / 9to5Mac : PSA: 773M email addresses and 21M passwords exposed by hackers, check yours here CircleID : A Data Dumb Exposes 773 Million Unique Email Addresses, 22 Million Passwords Chris Morris / Fortune : Here's How to Find Out if Your Email Was One of the 773 Million Exposed in Massive Data Breach Marius Nestor / Softpedia News : Hackers Expose 773M Email Addresses and 21M Passwords in Massive Breach Roland Moore-Colyer / Inquirer : 87GB data dump contains ‘largest ever’ collection of breached credentials Asha McLean / ZDNet : Over 87GB of email addresses and passwords exposed in Collection 1 dump Keumars Afifi-Sabet / IT PRO : Massive Collection #1 leak exposes 773m unique records online Yash Wate / Technology Personalized : More than 700 Million Email Credentials Leaked: Check if Yours is on the List Rob Thubron / TechSpot : Leaked database exposes 87GB of emails and passwords Tweets: Lorenzo Franceschi-Bicchierai / @lorenzofb : New: some are calling it a “monster breach,” and “the mother of all breaches.” But the “Collection #1” data dump of 773 million emails and passwords is actually not that bad. No need to panic, here's our advice. http://motherboard.vice.com/ ... Joseph Cox / @josephfcox : Basically chill and if you're inside an infosec team maybe don't bother pushing an alert about this unless you fancy confusing users for the next 12-24 hours http://twitter.com/... Joseph Cox / @josephfcox : Impact of ppl not knowing what websites are included in the Collection #1 dump: their email address comes up, they think their email address password has been breached. No, it's the password for a site you signed up to w/ that email. I'm getting msgs from lots of confused users @blmohr : “While it's difficult to confirm exactly where all that info came from, it appears to be something of a breach of breaches; that's to say, it claims to aggregate over 2,000 leaked databases that contain passwords whose protective hashing has been cracked.” http://www.wired.com/... @haveibeenpwned : New breach: The “Collection #1” credential stuffing list began broadly circulating last week and contains 772,904,991 unique email addresses with plain text passwords (now in Pwned Passwords). 82% of addresses were already in @haveibeenpwned. Read more: https://www.troyhunt.com/... @levelsio : I think it's time we start seeing emails as security keys too With so many account leaks it makes sense to start doing: username: l9hcknjkryfhqrunravvolyc@youranondomain .com password: ZosNRBKDcuXVKz7aCcdpdpdX And just save it in a passwd manager http://www.troyhunt.com/... Phosphore / @lorenzostella : The 733M collection loaded today on HIBP includes 56 italian data breach, but only 7 of these were previously unknown afaik. https://www.troyhunt.com/... Ashkan Soltani / @ashk4n : NBD, just 773M email address with a combined total of 1.16B username/passwords combinations just released on the Internet #security #thebigbreachhttps://t.co/dHOUOIAv1i
Context & Ripple Effects
The appearance of Collection #1 marks the moment breach data stopped arriving as isolated incident reports and started circulating as bulk commodity: ~773M unique email addresses and 21M passwords, some hashed, packaged for anyone to download. Coverage across CyberScoop, Fortune, and 9to5Mac converged on the same advice — check your address and stop reusing passwords — pointing readers toward breach-lookup services like HIBP.
The dump matters less for what is new in it than for what it aggregates: years of prior breaches stitched into one searchable corpus. Within weeks the corpus grew again with Collections #2-5, roughly 25B records on hacker forums and torrents, and by March researchers found an email validation company exposing 763M plaintext addresses — showing that both stolen and legitimately collected address data were ending up equally exposed.
First-order effects
- People whose addresses appear in the dump face immediate credential-stuffing risk wherever they reused passwords, which is why every outlet's first instruction was to check exposure and rotate credentials.
- Breach-notification lookup services absorb a sudden traffic surge as millions of readers verify their addresses against the new corpus.
Second-order effects
- The success of Collection #1 as a distribution format invites replication: within two weeks hackers are circulating Collections #2-5, nearly tripling the record count, confirming demand for pre-aggregated credential sets over raw breach files.
- Companies holding large email datasets — validators, marketers, platforms — come under researcher scrutiny as adjacent sources of the same exposure, as the March discovery of an unprotected validation database shows.
Third-order effects
- If the aggregation pattern holds, credential leaks compound rather than expire: the same corpus logic reappears in Syhunt's analysis of a 3.28B-password dump in 2021 and in the 184M-record exposed database found in 2025, making password reuse a systemic liability rather than an individual mistake.
- The economics shift toward whoever curates and distributes leaked credentials, pushing defenses from per-breach response toward continuous exposure monitoring and credential-hygiene enforcement at login.
The trend: Leaked credentials are consolidating into ever-larger, continuously redistributed commodity databases, turning individual breaches into permanent, compounding account-takeover infrastructure.