New Security Alert: 10 billion stolen passwords exposed in massive leak

The largest database of stolen passwords, containing nearly 10 billion unique records, has been leaked on a popular hacker forum. The Cybernews research group warns that this leak presents a significant threat to users who habitually reuse passwords.

What You Need To Know About The RockYou2024 Password Database

Cybernews security researchers have identified what they believe to be the largest aggregation of stolen and leaked credentials ever found on the BreachForums criminal underground forum. The RockYou2024 database reportedly includes an astounding 9,948,575,739 unique plaintext passwords. This compilation builds upon the previous RockYou 2021 database, which contained 8.4 billion passwords, incorporating around 1.5 billion new passwords. Spanning the years from 2021 to 2024, the latest credentials file is thought to contain data from a total of 4,000 massive databases of stolen credentials, covering at least two decades.

"The RockYou2024 leak essentially aggregates real-world passwords used by individuals globally," the researchers explained, adding that "exposing these passwords significantly increases the risk of credential stuffing attacks by threat actors.”

Credential stuffing attacks can be highly detrimental to both users and businesses. For instance, a recent series of attacks targeted prominent companies such as Santander, Ticketmaster, Advance Auto Parts, and QuoteWizard. These attacks were a direct consequence of credential stuffing efforts against the victims’ cloud service provider, Snowflake.

How to Protect Against RockYou2024

While there is no foolproof method to completely safeguard users whose passwords have been exposed, affected individuals and organizations should adopt mitigation strategies. The Cybernews research team recommends the following measures:

  1. Reset All Compromised Passwords: Immediately change the passwords for all accounts linked to the leaked passwords. It is crucial to choose strong, unique passwords that are not reused across multiple platforms.
  2. Enable Multi-Factor Authentication (MFA): Wherever possible, activate MFA. This adds an extra layer of security by requiring additional verification beyond just a password.
  3. Use Password Managers: Employ password manager software to securely generate and store complex passwords. Password managers help reduce the risk of password reuse across different accounts.

