The data breach notification service Have I Been Pwned has added 56 million email addresses and 124 million passwords stolen by infostealer malware from infected Windows devices to its database.
Key Points
- Have I Been Pwned integrated the new dataset into its search tool on June 15, 2026.
- The compromised credentials were harvested directly from individual user devices rather than through large-scale corporate server breaches.
- Infostealer malware silently extracts browser data, cookies, and stored passwords from infected systems over extended periods.
- Users can verify if their accounts were compromised by searching their email addresses on the Have I Been Pwned website.
- Security experts recommend enabling two-factor authentication and using unique passwords managed by a password manager to mitigate risks.