AUTO-UPDATED

124 million passwords added to breach database. Yours may be in there, too

The data breach notification service Have I Been Pwned has added 56 million email addresses and 124 million passwords stolen by infostealer malware from infected Windows devices to its database.

Key Points

  • Have I Been Pwned integrated the new dataset into its search tool on June 15, 2026.
  • The compromised credentials were harvested directly from individual user devices rather than through large-scale corporate server breaches.
  • Infostealer malware silently extracts browser data, cookies, and stored passwords from infected systems over extended periods.
  • Users can verify if their accounts were compromised by searching their email addresses on the Have I Been Pwned website.
  • Security experts recommend enabling two-factor authentication and using unique passwords managed by a password manager to mitigate risks.

Why it Matters

This update highlights a shift in cybercriminal tactics toward targeting individual end-user devices to bypass traditional corporate security measures. By harvesting credentials directly from personal computers, attackers can gain unauthorized access to multiple services, making robust password hygiene and multi-factor authentication essential for individual digital security.
PCWorld Published by Viviane Osswald
Read original