logo
Warning — 19 Billion Compromised Passwords Have Been Published Online

Warning — 19 Billion Compromised Passwords Have Been Published Online

Forbes06-05-2025

19 billion exposed passwords analyzed and it's not good news. getty
Update, May 6, 2025: This story, originally published May 3, has been updated with details of the SMS phishing threat posed by the Chinese Panda Shop cybercrime group, and an open letter to the cybersecurity industry asking why the phishing threat behind the stolen passwords epidemic has yet to be fixed.
In just the last few months, I have reported on confirmed lists of stolen passwords being made available on the dark web and in criminal forums that have risen from 800 million to 1.7 billion and even as high as 2.1 billion, mainly thanks to the rise and rise of infostealer malware attacks. But a new report has just blown even those shockingly large statistics out of the water with an analysis of 19 billion such passwords that are available online right now to any hackers who want to seek them out. The takeaway being that you need to take action now to prevent becoming a victim of the automatic password hacking machine epidemic. Forbes 884,000 Credit Cards Stolen With 13 Million Clicks By A Magic Cat By Davey Winder
Imagine having access to 19,030,305,929 passwords that were compromised by leaks and breaches over the course of 12 months from April 2024 and involving 200 security incidents. Imagine that only sources where email addresses were available for consumption alongside the stolen password were included in this massive database. Oh, and forget about including any of those word-list compilations, such as RockYou, that regularly do the rounds but are about as useful to a criminal hacker as a chocolate router. Finally, get to grips with the fact that this dataset only includes passwords that have become publicly available in criminal forums online. Once you digest all of this, you can appreciate how huge, in all senses of the word, this really is, especially to any hacker with criminal intent.
The analysis, published May 2 by the Cybernews research team, makes for truly eye-opening reading. It's so wide-ranging and security-scary in equal measure that it's hard to know where to start, so the beginning seems as good a place as any: password laziness and reuse. Of the 19,030,305,929 passwords that ended up exposed online, only 6% of them, or 1,143,815,266 if you like to be precise, were unique. Switch that around to 94% of them being reused across accounts and services, whether by the same or different people is moot, and you can see why the average cybercriminal gets very excited about the hacking potential such lists provide.
Now throw in that 42% of the passwords were short, way too short, being only 8-10 characters in length. That now opens up the hacking potential to brute force attacks as well as credential stuffing. Ah, yes, and it just keeps getting worse; 27% consisted of only lowercase letters and digits, no special characters or mixed case. Sigh. Forbes Google Says Critical Android 'No User Interaction' Attacks Underway By Davey Winder
According to Neringa Macijauskaitė, an information security researcher at Cybernews, 'the default password problem remains one of the most persistent and dangerous patterns in leaked credential datasets.' The analysis revealed that there were 53 million uses of admin and 56 million of password, for example. Changing these is one quick way to help mitigate against hackers, as Macijauskaitė said, 'attackers, too, prioritize them, making these passwords among the least secure.'
Not reusing your passwords, ever, not at all, is another prime mitigation recommendation. 'If you reuse passwords across multiple platforms, a breach in one system can compromise the security of other accounts, creating a domino effect,' Macijauskaitė warned. Meaning that even without any existing system compromise, attackers are able to exploit common password patterns in their hacking exploits. 'Attackers constantly harvest the latest credential dumps from exposed info-stealers and recently cracked hashes available publicly,' Macijauskaitė concluded. 'These fresh datasets enable waves of highly effective credential-stuffing attacks, often bypassing traditional security defenses.' Forbes Apple Passwords Attack Warning — Do Not Install This Update By Davey Winder An Open Letter To The Cybersecurity industry — Stopping The Stolen Passwords Problem
Paul Walsh, CEO of MetaCert and co-founder of the W3C Mobile Web Initiative in 2004, knows a thing or two about the problem of malicious messaging and has been involved in the creation of internet standards to protect against it. In conversation, Walsh told me that the latest national SMS phishing test carried out in March by MetaCert and including carriers such as AT&T, Verizon, T-Mobile and Boost Mobile, was as disappointing as it was expected. 'Every phishing message was still delivered,' Walsh told me, 'none were blocked, flagged, or rewritten.' This is, to say the least, given that the vast majority of phishing platforms are now developed to target mobile devices, overtaking email in this regard in 2024 according to ProofPoint. When you consider that phishing attacks, on whatever platform, are the starting point for most cyber attacks, it's no great leap to realize that the compromised passwords problem could be drastically reduced, if not stopped dead, by addressing the social engineering issue. Walsh has now written an open letter to the cybersecurity industry asking why the SMS phishing problem hasn't been solved ages ago?
'The cybersecurity industry has no shortage of experts in email security, endpoint protection, or network defense,' Walsh said, 'but when it comes to SMS infrastructure and security, there is a distinct lack of deep expertise.' His letter, therefore, is a call to action by security vendors who have 'built multi-billion-dollar businesses on stopping phishing in email and corporate networks,' Walsh said, 'yet the most trusted communication channel on the planet — SMS — remains an open, unprotected target.' Walsh demands that the same effort that has been made to address email security must now be made for the SMS vector because, he concluded, 'criminals have already moved in full force, and the industry is failing to respond.' Unless this happens, and happens with the full might of the cybersecurity industry behind it, I fear that I will be reporting about the compromise of user passwords for some time to come yet. Forbes 'Action Required Within 48 Hours' — PayPal Attack Warning Issued By Davey Winder From Passwords To Pandas
A new report by the security researcher team at Rescurity has confirmed just how dangerous the SMS phishing threat is. Having already established that the 'Smishing Triad' criminal gang has been operating since at least 2023, the Rescurity researchers have been keeping a close eye on the group of Chinese cybercriminals with very global ambitions. Using the by now de rigueur crime-as-a-service model, the Smishing Triad comprises multiple associates and leverages that scale to target victims all over the world.
Rescurity has reported how, according to the latest threat intelligence it has received, a single Chinese threat actor can distribute as many as 2 million phishing SMS text messages in a single day. The Smishing Triad, Rescurity said, 'could easily target up to 60,000,000 victims per month, or 720,000,000 per year,' or, to put it another way, every person in the U.S. — twice each year. The concern of Paul Walsh is brought sharply into focus when you realize that Smishing triad also uses network operator SMS gateways, alongside Google RCS and Apple's iMessage, to distribute their phishing attacks.
So, where does this story turn from passwords to pandas? In March, Rescurity identified yet another smishing kit that appeared to be using the same principles as the Smishing Triad service, and went by the name of Panda Shop. The Panda Shop kit has 'multiple Telegram channels and interactive bots to automate service delivery,' the Rescurity report said, providing distribution services primarily by way of Apple's iMessage and Android's RCS platforms. Furthermore, it would appear that the threat actors are purchasing, and purchasing in significant numbers, compromised Gmail accounts, as well as compromised Apple accounts, to help with the distribution efforts. Forbes Microsoft Issues June 1 Warning — Do Not Wait, Save Your Passwords Now By Davey Winder
'Like the Smishing Triad,' the Resecurity report confirmed, 'Panda Shop offers a customized smishing kit that can be deployed on any server.' The research team investigation concluded that it is highly likely that the Panda Shop group itself consists of some former Smishing Triad members who 'transitioned their operations under the new brand after being publicly shamed.' This theory is reinforced by the fact that the Panda Shop phishing kit structure, along with various scripting scenarios that have been analyzed by Resecurity, 'mimic the same product but include specific improvements and new supported templates.'
The scale of the smishing activity from Chinese threats actors, including Smishing Triad and now Panda Shop is, Resucurity warned, impressive. 'The spectrum of the crimes conducted due to smishing ranges from traditional carding and NFC-enabled fraud to money laundering chains, enabling fraudsters to process stolen funds,' Rescurity researchers said. There's more than just your passwords at stake from smishing or any phishing attacks; there's all the data that sits beyond it and the implications that the compromise of that and access to other services can have. 'Based on Resecurity's engagements with financial institutions globally,' the report concluded, 'this activity generates millions in losses annually.'

Orange background

Try Our AI Features

Explore what Daily8 AI can do for you:

Comments

No comments yet...

Related Articles

INFIDIGIT, INDIA'S LEADING SEO COMPANY, CONTINUES TO INNOVATE WITH CLIENT-CENTRIC DEVELOPMENTS THROUGH INFIGROWTH
INFIDIGIT, INDIA'S LEADING SEO COMPANY, CONTINUES TO INNOVATE WITH CLIENT-CENTRIC DEVELOPMENTS THROUGH INFIGROWTH

Yahoo

timean hour ago

  • Yahoo

INFIDIGIT, INDIA'S LEADING SEO COMPANY, CONTINUES TO INNOVATE WITH CLIENT-CENTRIC DEVELOPMENTS THROUGH INFIGROWTH

MUMBAI, India, June 2, 2025 /PRNewswire/ -- Infigrowth, the digital growth platform developed by Infidigit, India's leading SEO agency, has introduced its SEO Audit Module — a comprehensive, AI-powered solution designed to help brands precisely identify and resolve SEO issues impacting online visibility and performance. The SEO Audit Module offers a comprehensive site health checkup that helps brands gain clear insights into their website's performance. By analysing critical SEO factors through advanced AI-driven technology, it highlights key areas for improvement and provides actionable recommendations. This empowers businesses to enhance their search rankings and maintain a strong digital presence. The key features of our Automated SEO Audit Module include: 200+ Pointers Checked — Covers speed, mobile-friendliness, content, backlinks, and user experience. Weekly and Monthly Reports — Track SEO progress regularly. Clear Fix Recommendations — Step-by-step guidance for quick fixes. Issue Prioritisation — Focus on the most critical problems first. Page-Level Insights — Analyse and optimise individual pages. Team Collaboration — Share audits and work together in real-time. Kaushal Thakkar, CEO, Infidigit, said, "With over a decade of experience in SEO and digital marketing, Infidigit has a deep understanding of the challenges brands face in today's digital ecosystem. Infigrowth was created to address these challenges by offering a platform that combines AI-driven diagnostics with practical recommendations. Our SEO Audit Module enables brands to make data-driven decisions that lead to measurable growth, improved user experience, and a stronger online presence. It helps businesses stay agile and competitive in a constantly evolving landscape." Leveraging Infidigit's deep industry expertise and Infigrowth's AI capabilities, the SEO Audit Module delivers precise insights and actionable steps that enable brands to optimise their digital strategies, adapt swiftly to market shifts, and drive sustainable growth. Beyond the SEO Audit Module, Infigrowth provides a full suite of AI-powered features — including AI Overview tracking, SearchSense, RankTracker, and SERP Comparison. They are complemented by AI-driven keyword suggestions, seasonal trend tracking, competitor benchmarking, comprehensive SERP insights, and instant ranking alerts. Together, these features provide brands with a comprehensive and proactive SEO management experience. Looking ahead, Infidigit remains committed to continuous innovation and plans to introduce more advanced features on Infigrowth tailored to the evolving needs of digital marketers and businesses aiming to maintain a competitive edge. About Infigrowth Infigrowth is a cutting-edge digital growth platform developed by Infidigit, one of India's premier Digital Marketing agencies. Specialising in AI-powered SEO and data-driven marketing solutions, Infigrowth helps brands optimise their online presence, improve search rankings, and achieve measurable business growth. With a focus on innovation, actionable insights, and comprehensive digital tools, Infigrowth empowers businesses across industries to stay competitive in the evolving digital landscape. About Infidigit Founded in 2017, Infidigit is an AI-enabled digital growth partner that empowers top brands to achieve impactful results across SEO, Content, PPC, ASO, CRO, Website Development, and data-driven marketing strategies. As a pioneer in AI innovation within marketing, Infidigit has developed Infigrowth — a SaaS platform designed to simplify SEO for businesses of all sizes. Over the years, Infidigit has partnered with startups, MSMEs, and enterprises across diverse industries, helping them thrive in the fast-evolving digital economy. The company's commitment to excellence is demonstrated through over 65+ award-winning campaigns, recognised by prestigious platforms including SMX, APAC Search Awards, ET BrandEquity Shark Awards, Sparkies, and E4M IDMA. Video: View original content to download multimedia:

Blue Launches New Brand Campaign
Blue Launches New Brand Campaign

Associated Press

timean hour ago

  • Associated Press

Blue Launches New Brand Campaign

Humorous Presentation of 'Self-Service Insurance, Simplifying Complexity' Spotlight on Term Life Protection with 'Guaranteed Lowest Price in Town' HONG KONG SAR - Media OutReach Newswire - 2 June 2025 - Blue, Hong Kong's first digital life insurer, today unveiled its latest brand campaign, continuing the tagline 'Choose Blue, insurance is that simple'. The campaign uses humor to illustrate how Blue simplifies complex insurance processes through its online platform. The ads highlight Blue's simple and flexible protection plans, empowering customers to self-serve with ease — truly making life simpler with Blue. Blue, the first digital life insurer in Hong Kong, has launched its latest brand campaign with the slogan 'Choose Blue, insurance is that simple'. The campaign kicks off with a video advertisement that humorously illustrates how Blue's online insurance solutions simplify complexity, making it easy for customers to get insured. Blue 'WeCare Term Life Protection Plan TL3' promises customers the lowest price in town for the life protection. The campaign features two ad versions — 'Savage Mother-in-law' and 'Shy Bestie' (available on Blue's YouTube channel: & ). Set in what appears to be a casual dinner setting, the 'Savage Mother-in-law' ad humorously portrays a series of rapid demands and the daughter-in-law's witty responses, emphasizing the message: 'Life is complicated enough — fortunately, insurance doesn't have to be.' The 'Shy Bestie' ad delivers the line 'Love doesn't always come when you make the first move, but Blue always has you covered,' humorously reinforcing Blue's promise of the 'lowest price in town' for life protection. Beyond TV ads, Blue is rolling out the campaign across multiple online and offline channels this month, including bus and taxi ads, online banners, and social media content to amplify its reach. Mr. Danny Wu, VP & Head of Digital & Marketing of Blue, stated: 'We aim to break the traditional barriers of the insurance industry by simplifying complex terms and procedures, giving customers full control over their protection. We believe digitalization brings simplicity and flexibility that better meets evolving customer needs. With Blue, insurance is no longer complicated — customers can complete the entire application process in as fast as 5 minutes, truly making life simpler.' Blue 'WeCare Term Life Protection Plan TL3" — Guaranteed Lowest Price in Town Blue guarantees the lowest price in town during the first policy benefit term¹, ensuring customers get the best deal on term life protection — making it easier than ever to protect their loved ones. Key Features: Campaign Offers: Blue Insurance Limited is authorized and regulated by the Insurance Authority under the Insurance Ordinance (Cap. 41) to sell insurance products in Hong Kong. For full campaign and product details, terms and conditions, visit: . Terms and conditions apply to the above products and offers. Remarks: 1. 'Lowest Rate Guaranteed' compares the standard premiums of two quotations. To be eligible for the 'Lowest Rate Guaranteed', the two quotations must be on the same premium payment term, policy benefit term, issue age, sex, and smoking status, and is applicable to term life policies that are intended for online sale and in Hong Kong only. 'Lowest Rate Guaranteed' is not applicable for submitted applications and in-force policies. 2. Actual underwriting result depends on the age and health condition of the Insured. 3. While the Policy is in force, renewal is guaranteed at the end of the Policy Benefit Term, before the Life Assured's 96th birthday. For more details, please refer to the Product Summary and the Policy Provisions. Hashtag: #BlueHK #LiveEasy #DigitalInsurance #BlueisthatSimple #BrandCampaign #SimplifyingComplexity #TermLifeProtection #GuaranteedLowestPriceInTown The issuer is solely responsible for the content of this announcement. ABOUT BLUE Blue is the first digital life insurer in Hong Kong. It is a joint venture between Hillhouse Investment, a leading investment management firm with extensive investment experience, and Tencent Holdings Limited, a leading Internet value added services provider. Blue focuses on providing simple, flexible and valuable insurance solutions. It is committed to making people's lives easier by empowering them to take charge of their own protection. For more information, please visit

DOWNLOAD THE APP

Get Started Now: Download the App

Ready to dive into the world of global news and events? Download our app today from your preferred app store and start exploring.
app-storeplay-store