• Welcome to TechPowerUp Forums, Guest! Please check out our forum guidelines for info related to our community.

773 Million Credentials Leaked

Regeneration

NGOHQ.COM
Joined
Oct 26, 2005
Messages
3,077 (0.46/day)
A huge database of logins/passwords was leaked to MEGA a few days ago. Stolen from multiple hacked sources.

Collection #1 is a set of email addresses and passwords totalling 2,692,818,238 rows. It's made up of many different individual data breaches from literally thousands of different sources.

Source

How to check if yours is among them: https://haveibeenpwned.com
 
Last edited:
Joined
Mar 23, 2016
Messages
4,839 (1.64/day)
Processor Ryzen 9 5900X
Motherboard MSI B450 Tomahawk ATX
Cooling Cooler Master Hyper 212 Black Edition
Memory VENGEANCE LPX 2 x 16GB DDR4-3600 C18 OCed 3800
Video Card(s) XFX Speedster SWFT309 AMD Radeon RX 6700 XT CORE Gaming
Storage 970 EVO NVMe M.2 500 GB, 870 QVO 1 TB
Display(s) Samsung 28” 4K monitor
Case Phantek Eclipse P400S (PH-EC416PS)
Audio Device(s) EVGA NU Audio
Power Supply EVGA 850 BQ
Mouse SteelSeries Rival 310
Keyboard Logitech G G413 Silver
Software Windows 10 Professional 64-bit v22H2
Wth is this?

The fornite thing?
image-17.png
"Collection #1 is a set of email addresses and passwords totalling 2,692,818,238 rows. It's made up of many different individual data breaches from literally thousands of different sources."
https://www.troyhunt.com/the-773-million-record-collection-1-data-reach/
 
Joined
Nov 30, 2015
Messages
712 (0.23/day)
Location
Croatia
Processor Ryzen 5 3600 PRO
Motherboard AsRock B450 Pro4
Cooling Arctic Freezer 34 /w Noctua NF-P12
Memory Silicon Power XPower Zenith 2x8GB @1600 MHz
Video Card(s) Gigabyte RTX 2070 Super Gaming OC 8GB
Storage Crucial P5 Plus 1TB / Crucial MX 500 1TB
Display(s) Dell P2419H
Case Fractal Design Pop Air /w 3x Arctic P12 PWM
Audio Device(s) Creative Sound Blaster Z + Edifier R1000T4
Power Supply Super Flower Leadex III 650W
Mouse Microsoft Intelimouse Pro
Keyboard IBM KB-8926
Software Windows 10 Pro 64-bit
Benchmark Scores Turns on on the first try! Usually.
My mail is on the list, but my password isn't, so that's at least something.
 
Joined
Mar 23, 2016
Messages
4,839 (1.64/day)
Processor Ryzen 9 5900X
Motherboard MSI B450 Tomahawk ATX
Cooling Cooler Master Hyper 212 Black Edition
Memory VENGEANCE LPX 2 x 16GB DDR4-3600 C18 OCed 3800
Video Card(s) XFX Speedster SWFT309 AMD Radeon RX 6700 XT CORE Gaming
Storage 970 EVO NVMe M.2 500 GB, 870 QVO 1 TB
Display(s) Samsung 28” 4K monitor
Case Phantek Eclipse P400S (PH-EC416PS)
Audio Device(s) EVGA NU Audio
Power Supply EVGA 850 BQ
Mouse SteelSeries Rival 310
Keyboard Logitech G G413 Silver
Software Windows 10 Professional 64-bit v22H2
but my password isn't
NIST's guidance: check passwords against those obtained from previous data breaches

The Pwned Passwords service was created in August 2017 after NIST released guidance specifically recommending that user-provided passwords be checked against existing data breaches. The rationale for this advice and suggestions for how applications may leverage this data is described in detail in the blog post titled Introducing 306 Million Freely Downloadable Pwned Passwords. In February 2018, version 2 of the service was released with more than half a billion passwords, each now also with a count of how many times they'd been seen exposed. A version 3 release in July 2018 contributed a further 16M passwords and version 4 came in January 2019 along with the "Collection #1" data breach to bring the total to over 551M.
https://haveibeenpwned.com/Passwords
 
Joined
Jan 8, 2017
Messages
8,942 (3.36/day)
System Name Good enough
Processor AMD Ryzen R9 7900 - Alphacool Eisblock XPX Aurora Edge
Motherboard ASRock B650 Pro RS
Cooling 2x 360mm NexXxoS ST30 X-Flow, 1x 360mm NexXxoS ST30, 1x 240mm NexXxoS ST30
Memory 32GB - FURY Beast RGB 5600 Mhz
Video Card(s) Sapphire RX 7900 XT - Alphacool Eisblock Aurora
Storage 1x Kingston KC3000 1TB 1x Kingston A2000 1TB, 1x Samsung 850 EVO 250GB , 1x Samsung 860 EVO 500GB
Display(s) LG UltraGear 32GN650-B + 4K Samsung TV
Case Phanteks NV7
Power Supply GPS-750C
Pretty sure that site is bollocks. No matter what random string you write, it will either say its safe or not, but never that it doesn't exist.
 
Joined
Mar 10, 2015
Messages
3,984 (1.19/day)
System Name Wut?
Processor 3900X
Motherboard ASRock Taichi X570
Cooling Water
Memory 32GB GSkill CL16 3600mhz
Video Card(s) Vega 56
Storage 2 x AData XPG 8200 Pro 1TB
Display(s) 3440 x 1440
Case Thermaltake Tower 900
Power Supply Seasonic Prime Ultra Platinum
Could it be that safe means it isn't in there?
 
Joined
Jan 8, 2017
Messages
8,942 (3.36/day)
System Name Good enough
Processor AMD Ryzen R9 7900 - Alphacool Eisblock XPX Aurora Edge
Motherboard ASRock B650 Pro RS
Cooling 2x 360mm NexXxoS ST30 X-Flow, 1x 360mm NexXxoS ST30, 1x 240mm NexXxoS ST30
Memory 32GB - FURY Beast RGB 5600 Mhz
Video Card(s) Sapphire RX 7900 XT - Alphacool Eisblock Aurora
Storage 1x Kingston KC3000 1TB 1x Kingston A2000 1TB, 1x Samsung 850 EVO 250GB , 1x Samsung 860 EVO 500GB
Display(s) LG UltraGear 32GN650-B + 4K Samsung TV
Case Phanteks NV7
Power Supply GPS-750C
Also, I would refrain myself from using that password checker thing. It's quite ironic that it is this easy to get people to write their passwords randomly on some site.
 
Joined
Mar 23, 2016
Messages
4,839 (1.64/day)
Processor Ryzen 9 5900X
Motherboard MSI B450 Tomahawk ATX
Cooling Cooler Master Hyper 212 Black Edition
Memory VENGEANCE LPX 2 x 16GB DDR4-3600 C18 OCed 3800
Video Card(s) XFX Speedster SWFT309 AMD Radeon RX 6700 XT CORE Gaming
Storage 970 EVO NVMe M.2 500 GB, 870 QVO 1 TB
Display(s) Samsung 28” 4K monitor
Case Phantek Eclipse P400S (PH-EC416PS)
Audio Device(s) EVGA NU Audio
Power Supply EVGA 850 BQ
Mouse SteelSeries Rival 310
Keyboard Logitech G G413 Silver
Software Windows 10 Professional 64-bit v22H2
Joined
Nov 30, 2015
Messages
712 (0.23/day)
Location
Croatia
Processor Ryzen 5 3600 PRO
Motherboard AsRock B450 Pro4
Cooling Arctic Freezer 34 /w Noctua NF-P12
Memory Silicon Power XPower Zenith 2x8GB @1600 MHz
Video Card(s) Gigabyte RTX 2070 Super Gaming OC 8GB
Storage Crucial P5 Plus 1TB / Crucial MX 500 1TB
Display(s) Dell P2419H
Case Fractal Design Pop Air /w 3x Arctic P12 PWM
Audio Device(s) Creative Sound Blaster Z + Edifier R1000T4
Power Supply Super Flower Leadex III 650W
Mouse Microsoft Intelimouse Pro
Keyboard IBM KB-8926
Software Windows 10 Pro 64-bit
Benchmark Scores Turns on on the first try! Usually.

eidairaman1

The Exiled Airman
Joined
Jul 2, 2007
Messages
40,435 (6.58/day)
Location
Republic of Texas (True Patriot)
System Name PCGOD
Processor AMD FX 8350@ 5.0GHz
Motherboard Asus TUF 990FX Sabertooth R2 2901 Bios
Cooling Scythe Ashura, 2×BitFenix 230mm Spectre Pro LED (Blue,Green), 2x BitFenix 140mm Spectre Pro LED
Memory 16 GB Gskill Ripjaws X 2133 (2400 OC, 10-10-12-20-20, 1T, 1.65V)
Video Card(s) AMD Radeon 290 Sapphire Vapor-X
Storage Samsung 840 Pro 256GB, WD Velociraptor 1TB
Display(s) NEC Multisync LCD 1700V (Display Port Adapter)
Case AeroCool Xpredator Evil Blue Edition
Audio Device(s) Creative Labs Sound Blaster ZxR
Power Supply Seasonic 1250 XM2 Series (XP3)
Mouse Roccat Kone XTD
Keyboard Roccat Ryos MK Pro
Software Windows 7 Pro 64
Also, I would refrain myself from using that password checker thing. It's quite ironic that it is this easy to get people to write their passwords randomly on some site.

I wonder if OPs TPU account has been Pawned.

Looks like a Phishy in a Pharm
 
Joined
Dec 14, 2013
Messages
2,615 (0.69/day)
Location
Alabama
Processor Ryzen 2700X
Motherboard X470 Tachi Ultimate
Cooling Scythe Big Shuriken 3
Memory C.R.S.
Video Card(s) Radeon VII
Software Win 7
Benchmark Scores Never high enough
Agreed - Don't think hackers haven't noticed and neglected to "Get busy" with it.
Could be this is something setup to farm addys and passwords YOU give, making it easy for them to get.

I don't like the looks of it myself.
 

hat

Enthusiast
Joined
Nov 20, 2006
Messages
21,731 (3.41/day)
Location
Ohio
System Name Starlifter :: Dragonfly
Processor i7 2600k 4.4GHz :: i5 10400
Motherboard ASUS P8P67 Pro :: ASUS Prime H570-Plus
Cooling Cryorig M9 :: Stock
Memory 4x4GB DDR3 2133 :: 2x8GB DDR4 2400
Video Card(s) PNY GTX1070 :: Integrated UHD 630
Storage Crucial MX500 1TB, 2x1TB Seagate RAID 0 :: Mushkin Enhanced 60GB SSD, 3x4TB Seagate HDD RAID5
Display(s) Onn 165hz 1080p :: Acer 1080p
Case Antec SOHO 1030B :: Old White Full Tower
Audio Device(s) Creative X-Fi Titanium Fatal1ty Pro - Bose Companion 2 Series III :: None
Power Supply FSP Hydro GE 550w :: EVGA Supernova 550
Software Windows 10 Pro - Plex Server on Dragonfly
Benchmark Scores >9000
I concur. It hardly seems professional.

However, it's worth mentioning that evidently the password "jibbajabbajoo" is safe! Let's all use it.
 

eidairaman1

The Exiled Airman
Joined
Jul 2, 2007
Messages
40,435 (6.58/day)
Location
Republic of Texas (True Patriot)
System Name PCGOD
Processor AMD FX 8350@ 5.0GHz
Motherboard Asus TUF 990FX Sabertooth R2 2901 Bios
Cooling Scythe Ashura, 2×BitFenix 230mm Spectre Pro LED (Blue,Green), 2x BitFenix 140mm Spectre Pro LED
Memory 16 GB Gskill Ripjaws X 2133 (2400 OC, 10-10-12-20-20, 1T, 1.65V)
Video Card(s) AMD Radeon 290 Sapphire Vapor-X
Storage Samsung 840 Pro 256GB, WD Velociraptor 1TB
Display(s) NEC Multisync LCD 1700V (Display Port Adapter)
Case AeroCool Xpredator Evil Blue Edition
Audio Device(s) Creative Labs Sound Blaster ZxR
Power Supply Seasonic 1250 XM2 Series (XP3)
Mouse Roccat Kone XTD
Keyboard Roccat Ryos MK Pro
Software Windows 7 Pro 64
I concur. It hardly seems professional.

However, it's worth mentioning that evidently the password "jibbajabbajoo" is safe! Let's all use it.

Or shaqfuisgreat
 

rtwjunkie

PC Gaming Enthusiast
Supporter
Joined
Jul 25, 2008
Messages
13,909 (2.42/day)
Location
Louisiana -Laissez les bons temps rouler!
System Name Bayou Phantom
Processor Core i7-8700k 4.4Ghz @ 1.18v
Motherboard ASRock Z390 Phantom Gaming 6
Cooling All air: 2x140mm Fractal exhaust; 3x 140mm Cougar Intake; Enermax T40F Black CPU cooler
Memory 2x 16GB Mushkin Redline DDR-4 3200
Video Card(s) EVGA RTX 2080 Ti Xc
Storage 1x 500 MX500 SSD; 2x 6TB WD Black; 1x 4TB WD Black; 1x400GB VelRptr; 1x 4TB WD Blue storage (eSATA)
Display(s) HP 27q 27" IPS @ 2560 x 1440
Case Fractal Design Define R4 Black w/Titanium front -windowed
Audio Device(s) Soundblaster Z
Power Supply Seasonic X-850
Mouse Coolermaster Sentinel III (large palm grip!)
Keyboard Logitech G610 Orion mechanical (Cherry Brown switches)
Software Windows 10 Pro 64-bit (Start10 & Fences 3.0 installed)
Agreed - Don't think hackers haven't noticed and neglected to "Get busy" with it.
Could be this is something setup to farm addys and passwords YOU give, making it easy for them to get.

I don't like the looks of it myself.
No. What the site does is list websites you are or have been a member of who had data breaches. That’s the thing, it’s old and new. Some people will only have former breaches.

For instance, I was on half a dozen sites that were data breaches at one time. For example, NexusMods. That was about 4 years ago, and everyone that paid attention to their notifications changed their login info and passwords. The site is thus one of mine listed because it is associated with the email addy I input. It doesn’t mean people are currently breached.

People that pay attention and correct these things as websites warn them can input the email you use for sign ins and see that the only things listed are issues that have since been corrected.

Those that it shows a current problem, well then you might be asking why that associated website hasn’t warned you yet.
 
Joined
Sep 17, 2014
Messages
20,946 (5.97/day)
Location
The Washing Machine
Processor i7 8700k 4.6Ghz @ 1.24V
Motherboard AsRock Fatal1ty K6 Z370
Cooling beQuiet! Dark Rock Pro 3
Memory 16GB Corsair Vengeance LPX 3200/C16
Video Card(s) ASRock RX7900XT Phantom Gaming
Storage Samsung 850 EVO 1TB + Samsung 830 256GB + Crucial BX100 250GB + Toshiba 1TB HDD
Display(s) Gigabyte G34QWC (3440x1440)
Case Fractal Design Define R5
Audio Device(s) Harman Kardon AVR137 + 2.1
Power Supply EVGA Supernova G2 750W
Mouse XTRFY M42
Keyboard Lenovo Thinkpad Trackpoint II
Software W10 x64
How to check if yours is among them: https://haveibeenpwned.com

Are people here seriously questioning the legitimacy of haveibeenpwned.com? Wow... The site has only been around for over a decade doing the exact same thing. Good morning!

Same here wrt NexusMods, and my data was also leaked through Dungeons & Dragons Online. And yes, since those leaks, I get the occasional login on random accounts elsewhere for which I haven't bothered to change passwords. 2FA is my savior :D
 

95Viper

Super Moderator
Staff member
Joined
Oct 12, 2008
Messages
12,679 (2.23/day)
Are people here seriously questioning the legitimacy of haveibeenpwned.com? Wow... The site has only been around for over a decade doing the exact same thing. Good morning!

Yep, I question anything to do with someone wanting to collect data like this,
You go to that site... he logs your IP, you input your e-mail address. Now, you input your password to check it... and, remember, still got your IP.
They now have two lists. An e-mail one with IPs and a password list with IPs.
Compare the data; and, just match date, time, email addresses (& IPs), with Password (& IPs).
Just compiled me a nice list of possibilities.

Just my opinion.

Also, I am skeptical, too... looks like a scare tactic to get subscribers for his password manager.
 
Joined
Apr 12, 2013
Messages
6,750 (1.67/day)
Well there's always vpn, proxy, TOR & other alternatives if you don't want to be tracked/traced personally.
 

rtwjunkie

PC Gaming Enthusiast
Supporter
Joined
Jul 25, 2008
Messages
13,909 (2.42/day)
Location
Louisiana -Laissez les bons temps rouler!
System Name Bayou Phantom
Processor Core i7-8700k 4.4Ghz @ 1.18v
Motherboard ASRock Z390 Phantom Gaming 6
Cooling All air: 2x140mm Fractal exhaust; 3x 140mm Cougar Intake; Enermax T40F Black CPU cooler
Memory 2x 16GB Mushkin Redline DDR-4 3200
Video Card(s) EVGA RTX 2080 Ti Xc
Storage 1x 500 MX500 SSD; 2x 6TB WD Black; 1x 4TB WD Black; 1x400GB VelRptr; 1x 4TB WD Blue storage (eSATA)
Display(s) HP 27q 27" IPS @ 2560 x 1440
Case Fractal Design Define R4 Black w/Titanium front -windowed
Audio Device(s) Soundblaster Z
Power Supply Seasonic X-850
Mouse Coolermaster Sentinel III (large palm grip!)
Keyboard Logitech G610 Orion mechanical (Cherry Brown switches)
Software Windows 10 Pro 64-bit (Start10 & Fences 3.0 installed)
Yep, I question anything to do with someone wanting to collect data like this,
You go to that site... he logs your IP, you input your e-mail address. Now, you input your password to check it... and, remember, still got your IP.
They now have two lists. An e-mail one with IPs and a password list with IPs.
Compare the data; and, just match date, time, email addresses (& IPs), with Password (& IPs).
Just compiled me a nice list of possibilities.

Just my opinion.

Also, I am skeptical, too... looks like a scare tactic to get subscribers for his password manager.
You are spreading FUD, which as a moderator you definitely should know not to do.

Simple answer is don’t check any passwords with the site. You should be changing all your passwords regularly anyway. It’s just an informational tool that confirms sites you’ve been on that were breached at one time (and hopefully you fixed those logins back then) and (hopefully not) any currently breached sites you belong to. It does this with the email addy that you use for site registrations (hopefully you use an unimportant one).

The site is just informational, and as @Vayra86 said has been providing this service for many years.
 
Last edited:

95Viper

Super Moderator
Staff member
Joined
Oct 12, 2008
Messages
12,679 (2.23/day)
Well there's always vpn, proxy, TOR & other alternatives if you don't want to be tracked/traced personally.

True.
However, how many everyday users really use such. A lot, probably, have not heard of, or do not understand such.

You are spreading FUD, which as a moderator you definitely should know not to do.

Simple answer is don’t check any passwords with the site. You should be changing all your passwords regularly anyway. It’s just an informational tool that confirms sites you’ve been on that were breached at one time (and hopefully you fixed those logins back then) and (hopefully not) any currently breached sites you belong to. It does this with the email addy that you use for site registrations.

The site is just informational, and as @Vayra86 said has been providing this service for many years.

No FUD, just my opinion of a possiblility.
Vayra86 brought up the question; so yes, I answered Vayra86 and I am seriously questioning it.

Simple answer... I did not and have not used the site!
And, I agree, that a password should be change regularly, or, when you have doubt/suspicion.

And, personally, I do not care if the site has been there since day one.
 
Last edited:
Joined
Jan 8, 2017
Messages
8,942 (3.36/day)
System Name Good enough
Processor AMD Ryzen R9 7900 - Alphacool Eisblock XPX Aurora Edge
Motherboard ASRock B650 Pro RS
Cooling 2x 360mm NexXxoS ST30 X-Flow, 1x 360mm NexXxoS ST30, 1x 240mm NexXxoS ST30
Memory 32GB - FURY Beast RGB 5600 Mhz
Video Card(s) Sapphire RX 7900 XT - Alphacool Eisblock Aurora
Storage 1x Kingston KC3000 1TB 1x Kingston A2000 1TB, 1x Samsung 850 EVO 250GB , 1x Samsung 860 EVO 500GB
Display(s) LG UltraGear 32GN650-B + 4K Samsung TV
Case Phanteks NV7
Power Supply GPS-750C
That's not FUD, it's the least bit of common sense you can apply to these things. Online security in general is in a horrible state as it is, don't make it even worse if you can.
 
Joined
Jul 14, 2006
Messages
2,418 (0.37/day)
Location
People's Republic of America
System Name It's just a computer
Processor i9-14900K Direct Die
Motherboard MSI Z790 ACE MAX
Cooling Dual D5T Vario, XSPC BayRes, Nemesis GTR560, NF-A14-iPPC3000PWM, NF-A14-iPPC2000, HK IV Pro Nickel
Memory G.SKILL F5-7200J3646F24GX2-TZ5RK
Video Card(s) eVGA RTX2080 FTW3 Ultra
Storage Samsung 990 PRO 1TB M.2
Display(s) LG 32GK650F
Case Thermaltake Xaser VI
Audio Device(s) Auzentech X-Meridian 7.1 2G/Z-5500
Power Supply Seasonic Prime PX-1300
Mouse Logitech
Keyboard Logitech
Software Win11PRO
Seems phishy to me...
 
Joined
Dec 31, 2009
Messages
19,366 (3.70/day)
Benchmark Scores Faster than yours... I'd bet on it. :)
However, how many everyday users really use such. A lot, probably, have not heard of, or do not understand such.
OT... but at least at OCF, I was surprised how many users 'hid' behind a VPN. Now, it isnt a lot...but it was a lot more than I would have ever expected.
 
Joined
Sep 17, 2014
Messages
20,946 (5.97/day)
Location
The Washing Machine
Processor i7 8700k 4.6Ghz @ 1.24V
Motherboard AsRock Fatal1ty K6 Z370
Cooling beQuiet! Dark Rock Pro 3
Memory 16GB Corsair Vengeance LPX 3200/C16
Video Card(s) ASRock RX7900XT Phantom Gaming
Storage Samsung 850 EVO 1TB + Samsung 830 256GB + Crucial BX100 250GB + Toshiba 1TB HDD
Display(s) Gigabyte G34QWC (3440x1440)
Case Fractal Design Define R5
Audio Device(s) Harman Kardon AVR137 + 2.1
Power Supply EVGA Supernova G2 750W
Mouse XTRFY M42
Keyboard Lenovo Thinkpad Trackpoint II
Software W10 x64
Yep, I question anything to do with someone wanting to collect data like this,
You go to that site... he logs your IP, you input your e-mail address. Now, you input your password to check it... and, remember, still got your IP.
They now have two lists. An e-mail one with IPs and a password list with IPs.
Compare the data; and, just match date, time, email addresses (& IPs), with Password (& IPs).
Just compiled me a nice list of possibilities.

Just my opinion.

Also, I am skeptical, too... looks like a scare tactic to get subscribers for his password manager.

Take the effort to click on a few tabs on that site and you get indepth API info, code to use and implement, etc. Ive seen my share of scammy sites but this is not how those tend to look. Spotless English clearly written by a native speaker, and accurate results one can recognize without exceptions. The API works.

This is no BS site. The fact so many of you havent heard of it, to me is honestly stunning, more so than your thoughts of its legitimacy or purpose.

Due diligence pls? Click around a bit and see for yourself ...

Oh its half a decade, I see...
https://en.m.wikipedia.org/wiki/Have_I_Been_Pwned?
 
Last edited:
Top