/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

← → days · ↑ ↓ browse · Enter similar · o open

Hacker claims to have posted ~617M online account details stolen from 16 hacked companies for sale on the dark web; MyHeritage and 500px confirm stolen data

Are You On The List? Tweets: @theregister : FYI: We've sighted a trove of 617m accounts, pulled from 16 ‘hacked’ websites, for sale on the dark web.The data appears legit. It includes email addresses and hashes taken from MyHeritage in 2017 that have been verified by the biz and is the first time they've gone on sale @theregister : Now @EyeEm confirms it was hacked, as we reported http://www.theregister.co.uk/ ... 22 million EyeEm account details, including email addresses and SHA1-hashed passwords, for sale on the dark web for 0.289 BTC... http://twitter.com/... Iain Thomson / @iainthomson : 620 million accounts stolen from 16 hacked websites now for sale on dark web, seller boasts https://www.theregister.co.uk/ ... via @theregister We've spent days working if this is legit. Looks that way. @theregister : UPDATE: 500px confirms its systems were hacked, data leaked in this week's 617 million account dump - more to follow “We are working on notifying our entire user base, however, given the amount of users affected, this task will span one day at minimum.” http://www.theregister.co.uk/ ... Raj Samani / @raj_samani : 620m accounts stolen from 16 hacked websites now for sale on #darkweb all for “less than $20,000 in #Bitcoin” https://www.theregister.co.uk/ ... #cybercrime Joe Janecek / @joejanecek : Listed: Dubsmash, MyFitnessPal, MyHeritage, ShareThis, HauteLook, Animoto, EyeEm, 8fit, Whitepages, Fotolog, 500px, Armor Games, BookMate, CoffeeMeetsBagel, Artsy, and DataCamp. http://twitter.com/...

The Register Chris Williams

Context & Ripple Effects

The seller's playbook has a lineage: the same broker model surfaced when the hacker behind LinkedIn's 117M database claimed a 360M Myspace email trove, and the 2016 Tessa88-vs-Peace rivalry showed hackers stockpiling credentials from Facebook and Instagram before putting them up for sale (rival hackers Tessa88 and Peace). What changed by 2019 is scale and packaging — 16 companies' worth of data bundled into one dark-web listing.

MyHeritage is the anchor victim here: it disclosed in mid-2018 that account info for 92M+ users was exposed, including hashed passwords (its own breach disclosure), so this listing is the first time that 2017-stolen data has actually gone on sale — turning a known incident into an active marketplace event.

First-order effects

  • Users of the 16 named companies — with MyHeritage, 500px, and EyeEm already confirming their data is in the dump — face immediate credential-stuffing risk wherever they reused passwords, forcing password resets and breach notifications.
  • The verified inclusion of MyHeritage hashes lends credibility to the whole 617M-account listing, raising pressure on the other 14 companies (Animoto, MyFitnessPal, Dubsmash, HauteLook, Armor Games among them) to confirm or deny before the data spreads.

Second-order effects

  • The per-trove pricing — 22M EyeEm records listed at 0.289 BTC — sets a visible price floor that other sellers can undercut, and the 2020 follow-on where 18 companies' data was shared free on a forum (data from Dave and Wattpad posted for free) shows how quickly paid listings collapse into free distribution.
  • Confirmation-by-victim becomes the burden of proof: each company that validates its slice (as MyHeritage did) de-risks the buyer's purchase of the remaining unverified troves, effectively subsidizing sales of the other 14 breaches.

Third-order effects

  • Because the stolen data is mostly emails plus password hashes from long-forgotten services, the structural exposure is cross-site: a niche photo or game app breach functions as a skeleton key to users' primary email and social accounts, pushing the industry toward mandatory breach-notification and hash-algorithm standards.
  • The economics point toward commoditization — if large multi-company troves keep migrating from paid listings to free forum drops, the value shifts from selling data to weaponizing it (account takeover, spam, extortion), which is the pattern later visible in the 23andMe credential-harvesting breach (6.9M ancestry profiles taken via ~14K accounts).

The trend: Stolen credential troves are consolidating from single-company sales into bulk multi-company dark-web inventories, with victims' own confirmations serving as quality assurance for the resale market.