The 773 Million Record Collection #1 Data Breach

Page 1 of 5 123 ... LastLast
    The 773 Million Record Collection #1 Data Breach

    The 773 Million Record Collection #1 Data Breach

    Troy Hunt: The 773 Million Record "Collection #1" Data Breach. 17 January 2019

    Last Updated: 17 Jan 2019 at 22:07

    Many people will land on this page after learning that their email address has appeared in a data breach I've called "Collection #1". Most of them won't have a tech background or be familiar with the concept of credential stuffing so I'm going to write this post for the masses and link out to more detailed material for those who want to go deeper.

    Source: Troy Hunt; The 773 Million Record "Collection #1" Data Breach

    Related Search: The 773 Million Record "Collection #1" Data Breach (DuckDuckGo)
    Anak's Avatar Posted By: Anak
    17 Jan 2019


  1. Posts : 1,800
    10 Home 64-bit | v22H2 | Build - 19045.3930
       #1

    Wow, over 600 views and no one has any thoughts about this?

    Back at the end of 2013 when Troy Hunt started Have I Been Pwned? (HIBP?) I looked up my main email addy and yep, it came up as having been harvested on two sites that eventually became obsolete for me. I did take the usual remediation such as changing some user names, all passwords and added two-step verification where applicable, I didn't have any problems with my email except for a slight increase in spam that has since dwindled to about three per month.
    I said some usernames. I didn't want the hassle of changing my main email addy mainly because of all the updates to my contacts, but I did strengthen its password. (I know, I know).

    Over the years since then my internet usage was pretty boring until the other day when I received an email from Troy's HIBP? site informing me that I was listed again somewhere deep within the bowels of the 773 million record and the two original obsolete sites were listed again.

    My thoughts:
    • Since HIBP? has the record of my old addy (and that's how I got HIBP?'s notice about the 773) Does that mean the 773 record is redoing the list from the two obsolete sites? I believe the only way to tell is to check my other email addy's; Right?
    • What are anyone's thoughts on staying signed-in or out to/for a site? Some I do stay in like here at TenForums, but other more sensitive sites I always sign-out. I believe that even though your signed-out a black hat has your addy and just needs to crack your password.
    • If signed-in does the web site know an intrusion is being made based on a different unique computer ID being used by a hacker?
      My Computers


  2. Posts : 12,801
    Windows 11 Pro
       #2

    I saw the post when you posted it and read Troy's blog about it. I'm unsure of what to say except more of the same. After the Equafax breach I'm not sure there is anyone in the US whose personal info is not all over the net. I try to change passwords fairly often with the 'important' ones. I have some I'm not too worried about, but probably should be. I just have too many to keep up with. My email was compromised way back when the Linux Mint forum was breached several years ago.

    I would guess it depends on the site security. I have wondered if you stay signed in it should raise some red flags somewhere if someone tries to sign in again from a different computer. Especially the financial sites. I don't know if that is true but it seems it should be.

    BTW, I am on the Collection #1 list as well as a couple of others.
      My Computer


  3. Posts : 26
    win10 64x home retail
       #3

    Well, its not a new breach but an old one,, who resurfaced again, two or three years old, read this somewhere..
    For me, two years ago i begon the use of Lastpass with 2fa if possible.
      My Computer


  4. Posts : 1,481
    W10 22H2 19045.3031
       #4

    I had an email address for 10+ yrs. All of a sudden, I started getting 40+ spam emails per day and eventually went to my ISP and cancelled that address. Just checked it on Pwned and it is not there.
      My Computers


  5. Posts : 27,183
    Win11 Pro, Win10 Pro N, Win10 Home, Windows 8.1 Pro, Ubuntu
       #5

    If your Email address pops up on haveibeenpwned there is a separate site to check passwords separately Have I Been Pwned: Pwned Passwords

    Troy Hunt: Introducing 306 Million Freely Downloadable Pwned Passwords
      My Computers


  6. Posts : 1,560
    Windows 10 Home 20H2 64-bit
       #6

    These are sites that has been breached with the associated e-mail, correct? I mean, my E-mail have main password, but I assume this means different sites that has been breached, and that the linked mail address/password for that site has been compromised and pasted/collected? I never use the same password on any site.
      My Computer


  7. Posts : 27,183
    Win11 Pro, Win10 Pro N, Win10 Home, Windows 8.1 Pro, Ubuntu
       #7

    Faith said:
    These are sites that has been breached with the associated e-mail, correct? I mean, my E-mail have main password, but I assume this means different sites that has been breached, and that the linked mail address/password for that site has been compromised and pasted/collected? I never use the same password on any site.
    Some of these email accounts in this breach have old passwords(if you change them every once and a while like I do)
    My gmail was pawnd, but my current password is good.

    This is Troy Hunt, the owner of HIBP,

      My Computers


  8. Posts : 1,560
    Windows 10 Home 20H2 64-bit
       #8

    I want to know how these passwords have been collected. Have Google and Microsoft leaked my main password? If my mail address is on the list it means it's been compromised via another site, right? Then my question is, do they collect different passwords on the breached/leaked sites on the same associated mail address?
      My Computer


  9. Posts : 27,183
    Win11 Pro, Win10 Pro N, Win10 Home, Windows 8.1 Pro, Ubuntu
       #9

    Faith said:
    I want to know how these passwords have been collected. Have Google and Microsoft leaked my main password? If my mail address is on the list it means it's been compromised via another site, right? Then my question is, do they collect different passwords on the breached/leaked sites on the same associated mail address?
    The servers get breached on the sites you use, and then the same email and password(if cracked, or if god forbid the site left them in the open instead of hashing them with SHA256(or higher), is tested on other popular sites.

    Always create a different password when joining a new site, never use your email accounts password.
    Most sites like Ten Forums just need the email address to validate you wanted to join, and the password yoou created for here, is to make sure only you have access to your account here,
      My Computers


 

  Related Discussions
Our Sites
Site Links
About Us
Windows 10 Forums is an independent web site and has not been authorized, sponsored, or otherwise approved by Microsoft Corporation. "Windows 10" and related materials are trademarks of Microsoft Corp.

© Designer Media Ltd
All times are GMT -5. The time now is 20:43.
Find Us




Windows 10 Forums