All those "16 billion passwords" headlines in June sounded hyperbolic, didn't they? Yeah, turns out they were: https://www.troyhunt.com/that-16-billion-password-story-aka-data-troll/
Creator of @haveibeenpwned. Microsoft Regional Director and MVP. Pluralsight author. Online security, technology and “The Cloud”. Australian.
All those "16 billion passwords" headlines in June sounded hyperbolic, didn't they? Yeah, turns out they were: https://www.troyhunt.com/that-16-billion-password-story-aka-data-troll/
New stealer logs: In June, news broke of a "16 billion password" breach, though the data turned out to be mostly previously seen stealer logs. 109M unique email addresses have been loaded as "Data Troll", with 96% already in @haveibeenpwned. More: https://haveibeenpwned.com/breach/DataTrollStealerLogs
This is really just a little thing, but we've started integrating geo-targeted resources into HIBP to direct people to guidance from their local gov. Hopefully it'll help a few more people get more contextual advice, starting with our Kiwi friends: https://www.troyhunt.com/get-pwned-get-local-advice-from-a-trusted-gov-source/
Weekly update is up! Talking Science with Dr Karl; Welcoming Guardio to the Partner Program; Launching a Reseller Portal; Pairing Dozens of Shelleys https://www.troyhunt.com/weekly-update-464/
New breach: Unigame (maker of Hunter Online) had 844k records breached in 2019. Impacted data included email addresses and salted MD5 password hashes. 69% were already in @haveibeenpwned. Read more: https://cybernews.com/security/billions-passwords-credentials-leaked-mother-of-all-breaches/
Going live with my weekly vid in 30 mins! Talking Science with Dr Karl; Welcoming Guardio to the Partner Program; Launching a Reseller Portal; Pairing Dozens of Shelleys https://youtube.com/live/yasL8EnivOo?feature=share
We're very happy to welcome Guardio to @haveibeenpwned's partner program! Guardio does a fantastic job of protecting people from the sorts of scams we know our users often fall victim to. Here's what we're doing with them: https://www.troyhunt.com/welcoming-guardio-to-have-i-been-pwneds-partner-program/
@kasperd yep, just too many people trying it on and making noise that drowns out the actually important stuff. It sucks.
@adisonverlice forcing identity verification in the way they did (ironically, to make it a “safe space”) was always going to create risk
Weekly update is up! Tea Spilled in Crazy Breach; Trying to Shake Me Down for $30k; The IoT Light Switch Saga Continues; Pi-hole Pwned https://www.troyhunt.com/weekly-update-463/
New breach: A vulnerability in the GiveWP WordPress plugin exposed the names and email addresses of 30k donors to the Pi-hole network-wide ad blocking project this week. 73% were already in @haveibeenpwned. Read more: https://pi-hole.net/blog/2025/07/30/compromised-donor-emails-a-post-mortem/
Going live with my weekly vid in 30 mins! Tea Spilled in Crazy Breach; Trying to Shake Me Down for $30k; The IoT Light Switch Saga Continues https://youtube.com/live/OPePBIQH0hs?feature=share
Weekly update is up! Breaches, Injunctions, Thoughts and Prayers; Teespring Sucks; Microsoft MVP and RD Again; Creams Cafe Breach https://www.troyhunt.com/weekly-update-462/
Going live with my weekly vid in 30 mins! Breaches, Injunctions, Thoughts and Prayers; Teespring Sucks; Microsoft MVP and RD Again; Creams Cafe Breach https://youtube.com/live/c4Y6z-EuGTU?feature=share
@dplattsf we don’t have any control over the image format, never seen a report of that before so seems like a pretty niche scenario
@jenk @SQLAllFather I used lots of words to describe them that I couldn’t put in this blog post 🤬 https://www.troyhunt.com/good-riddance-teespring-hello-fourthwall/
New breach: 160k customer records were allegedly obtained from Creams Cafe in May. Data included email and physical address, name and phone number. Creams Cafe did not respond to repeated attempts to report the breach. 76% were already in @haveibeenpwned https://haveibeenpwned.com/
Wow, this is starting to feel like a long time! Very happy to be renewed for Microsoft RD and MVP again 😊 https://www.troyhunt.com/11-years-of-microsoft-regional-director-and-15-years-of-mvp/
Two months ago, we launched a totally revamped @haveibeenpwned site and with it, a merch store using Teespring. They've been abysmal, and I've got to apologise to our supporters who purchased through them. But there's hope! Here's what we've now done: https://www.troyhunt.com/good-riddance-teespring-hello-fourthwall/
Weekly update is up! Stripe, Invoicing and Emails; Omnicuris Breach; MaReads Breach; HIBP and Chromebooks; Welcoming Aura to HIBP Partnership https://www.troyhunt.com/weekly-update-461/