Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
mass-credential-exposurecredential-stealer-activityunderground-data-leakcybercrime-service-ecosystem

Massive Aggregation of Stolen Credentials Added to Have I Been Pwned

Updated 3mo agoFirst seen Oct 22, 20256 sources

Have I Been Pwned (HIBP) has incorporated a new dataset containing 183 million unique stolen email and password pairs, sourced and aggregated by a U.S. college student known as Ben for the cybersecurity company Synthient. The dataset, totaling 23 billion rows and 3.5 terabytes, was compiled from infostealer malware logs, Telegram groups, Tor sites, and various underground forums, reflecting the industrial scale at which credentials are stolen, traded, and reused across the dark web. Security experts note that this aggregation highlights the persistent threat posed by credential theft, password reuse, and the automation of attacks, which collectively undermine digital trust and make traditional defenses less effective.

The Synthient dataset is notable for its breadth, as it combines real credentials captured from infostealer malware with credential stuffing lists, rather than being the result of a single breach. This collection process demonstrates how stolen credentials move through a digital supply chain, being shared, merged, and resold repeatedly. The exposure of such a vast number of credentials underscores the importance of maintaining visibility into leaked data, enforcing multi-factor authentication, and adopting stronger authentication practices to mitigate the risks associated with widespread credential compromise.

Share:
Massive Aggregation of Stolen Credentials Added to Have I Been Pwned
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

3 events from the most recent confirmed update back to the earliest known activity.

3 EVENTS
Oct 27, 20258mo ago

Google disputes claims of a massive Gmail breach tied to the data

Google said reports framing the exposed records as a new large-scale Gmail data breach were false, clarifying that the credentials were aggregated from infostealer activity and other sources rather than a direct compromise of Google. The response helped reframe the incident as credential aggregation, not a single-platform breach.

Oct 21, 20258mo ago

Have I Been Pwned adds 183 million unique stolen credentials

Troy Hunt added 183 million unique email address and password pairs from the Synthient dataset to Have I Been Pwned. The update made the stolen credentials searchable for affected users and highlighted the scale of industrialized credential theft.

Synthient compiles a massive credential corpus from stealer logs and forums

A U.S. college student known as Ben, working for Synthient, assembled a dataset containing roughly 23 billion rows from infostealer malware logs, Telegram groups, and online forums. The collection represented aggregated stolen credentials from many sources rather than a single breach.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

7 LINKEDOpen in app
Organizations
5 linked
Keeper SecurityHave I Been PwnedRapid7BitwardenSynthient
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.