The UK's National Crime Agency shares 585M+ compromised passwords, found during an investigation, with Have I Been Pwned, after the FBI started sharing in May
Catalin Cimpanu / The Record :
Context & Ripple Effects
Have I Been Pwned had just made its Pwned Password code open source while the FBI began supplying passwords uncovered in investigations. The National Crime Agency's contribution extends that law-enforcement-to-password-checking pipeline beyond a single U.S. agency.
First-order effects
- Have I Been Pwned gains more than 585 million compromised-password records from the National Crime Agency's investigation, expanding the data available through its password-checking service.
- The National Crime Agency turns investigation-derived credentials into a defensive resource, following the FBI's May sharing arrangement.
Second-order effects
- Organizations and services that use Have I Been Pwned's Pwned Password data can screen against a larger set of known compromised credentials without obtaining the National Crime Agency's underlying investigation material.
- The NCA's participation gives the FBI's earlier password-sharing commitment a cross-border counterpart, making Have I Been Pwned a more central destination for credentials found by investigators.
Third-order effects
- If more agencies adopt this model, compromised-password intelligence may increasingly move from closed investigations into shared security infrastructure, with Have I Been Pwned acting as a public-facing distribution layer.
The trend: Law-enforcement agencies are beginning to operationalize credentials recovered in investigations as shared inputs to password-defense services.