Have I Been Pwned: hackers stole 71K+ Nvidia staff credentials, including email IDs and Windows password hashes, many of which were “cracked and circulated”
Carly Page / TechCrunch :
Context & Ripple Effects
What began as an incident that caused Nvidia internal outages was followed by Nvidia’s confirmation that employee and proprietary information had leaked. The credential disclosure adds a usable identity layer to the same breach, rather than just a loss of internal files.
The related coverage also records LAPSUS$ using the stolen material as leverage over Nvidia’s GPU policies, while the group’s cache included proprietary information. That makes the circulation of cracked employee password hashes an immediate security issue alongside the public pressure campaign.
First-order effects
- Nvidia must treat the affected workforce identities as exposed because attackers circulated cracked Windows password hashes alongside employee email addresses, increasing the risk of targeted account compromise.
- Employees whose credentials were cracked face more credible phishing and password-reuse attacks, since attackers can pair an Nvidia identity with a known password.
Second-order effects
- Nvidia’s incident response expands from protecting proprietary data to securing employee access paths, requiring priority attention to accounts tied to the circulated credentials.
- The breach’s operational risk extends beyond files: researchers subsequently found leaked Nvidia code-signing certificates used to sign Windows malware, showing how multiple stolen assets from one intrusion can create distinct attack routes.
Third-order effects
- The Nvidia case points to breaches being assessed by the combined exploitability of identity data, source material, and signing credentials—not solely by the volume of data taken.
- If attackers continue to package credential leaks with public coercion, chipmakers and other technology suppliers will face security incidents that simultaneously threaten workforce access, software trust, and product-policy control.
The trend: High-profile intrusions are evolving into multi-asset campaigns in which stolen employee identities, proprietary material, and software-trust credentials reinforce one another.