/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

← → days · ↑ ↓ browse · Enter similar · o open

The UK's National Crime Agency shares 585M+ compromised passwords, found during an investigation, with Have I Been Pwned, after the FBI started sharing in May

Catalin Cimpanu / The Record :

The Record Catalin Cimpanu

Context & Ripple Effects

Have I Been Pwned had just made its Pwned Password code open source while the FBI began supplying passwords uncovered in investigations. The National Crime Agency's contribution extends that law-enforcement-to-password-checking pipeline beyond a single U.S. agency.

First-order effects

  • Have I Been Pwned gains more than 585 million compromised-password records from the National Crime Agency's investigation, expanding the data available through its password-checking service.
  • The National Crime Agency turns investigation-derived credentials into a defensive resource, following the FBI's May sharing arrangement.

Second-order effects

  • Organizations and services that use Have I Been Pwned's Pwned Password data can screen against a larger set of known compromised credentials without obtaining the National Crime Agency's underlying investigation material.
  • The NCA's participation gives the FBI's earlier password-sharing commitment a cross-border counterpart, making Have I Been Pwned a more central destination for credentials found by investigators.

Third-order effects

  • If more agencies adopt this model, compromised-password intelligence may increasingly move from closed investigations into shared security infrastructure, with Have I Been Pwned acting as a public-facing distribution layer.

The trend: Law-enforcement agencies are beginning to operationalize credentials recovered in investigations as shared inputs to password-defense services.

Discussion

  • @z3r0trust @z3r0trust on x
    “Troy Hunt, the creator of the Have I Been Pwned (HIBP) service, announced today that after importing and parsing the data from the NCA a set of 225,665,425 passwords were found to be completely new.” https://www.bleepingcomputer.com/ ...
  • @campuscodi Catalin Cimpanu on x
    The UK NCA becomes the second law enforcement agency (after the FBI) to share hacked data with HIBP. It recently shared 585 million compromised passwords (of which 225 million were unique) with HIBP, data it found on a compromise UK cloud storage account https://therecord.media/.…
  • @troyhunt Troy Hunt on x
    I'm enormously pleased today to finally deliver on 2 long-standing promises: open sourced HIBP code and an ingestion pipeline for newly seen passwords provided by law enforcement agencies, beginning with the FBI: https://www.troyhunt.com/...