Security experts have found a 41-gigabyte (GB) archive containing over 1.4 billion unencrypted user credentials on the Dark Web, which had been updated at the end of November.
The huge database consisting over 1.4 billion email addresses, passwords, and other credentials in plain text was discovered online on December 5 by security researchers from the California-based identity threat intelligence company, 4iQ. The file found is not the result of a new data breach, but an amalgamation of those from several past breaches, collated into a single database that is over 41GB in size.
According to Julio Casal, 4iQ founder and chief technology officer, the archive is the most massive aggregation of various leaks that’s ever been found in the Dark Web until date.
“While scanning the deep and dark web for stolen, leaked or lost data, 4iQ discovered a single file with a database of 1.4 billion clear text credentials — the largest aggregate database found in the dark web to date.” reads a post published by 4iQ on Medium.
“None of the passwords are encrypted, and what’s scary is the we’ve tested a subset of these passwords and most of the have been verified to be true.”
The 41GB file aggregates data from a collection of over 250 previous data breaches and credential lists, which include popular websites such as LinkedIn, Netflix, Last.FM, MySpace, Zoosk, and YouPorn, as well as games like Minecraft and Runescape.
The data was organized and indexed alphabetically by the collector, and the total amount of credentials is 1,400,553,869.
“The breach is almost two times larger than the previous largest credential exposure, the Exploit.in combo list that exposed 797 million records.” continues Julio Casal.
“This new breach adds 385 million new credential pairs, 318 million unique users, and 147 million passwords pertaining to those previous dumps.”
An extensive examination of the archive gave researchers a glimpse of some of the most commonly used weak passwords by the users, which includes passwords such as “123456,” “123456789,” “qwerty,” “password,” and “111111.”
While some of the breaches happened a few years ago, expert observed that the cybercriminals still have good chances of accessing personal accounts as users tend to reuse the easy and common passwords or the same passwords for multiple online services.
“Since the data is alphabetically organized, the massive problem of password reuse — — same or very similar passwords for different accounts — — appears constantly and is easily detectable.” states the post.
The researchers highlighted that 14% of the 1.4 billion records (almost 200 million) had not previously been available in readily-usable decrypted form. In other words, the passwords and usernames, were new and in plain text.
“We compared the data with the combination of two larger clear text exposures, aggregating the data from Exploit.in and Anti Public. This new breach adds 385 million new credential pairs, 318 million unique users, and 147 million passwords pertaining to those previous dumps.” continues the expert.
While it is unclear who is behind the collection of billions of user credentials, the culprits have however left the Bitcoin and Dogecoin wallet addresses accessible for anyone who wants to donate for their alleged efforts.
In order to stay safe from potential cyber-attacks, we recommend our readers to use strong passwords, avoid using same passwords on multiple sites, and regularly keep changing your passwords.