This is likely the biggest password leak ever: nearly 10 billion credentials exposed

The 'RockYou2024' leak could give hackers a huge upper hand.
By Matt Binder  on 
Login screen
Hackers now have a record-breaking database of nearly 10 billion leaked passwords at their disposal. Credit: Jens Büttner/picture alliance via Getty Images

Cybersecurity researchers are calling it the largest password compilation leak of all time.

On July 4, a newly registered user on a popular hacking forum posted a file containing nearly 10 billion compromised passwords in plaintext. The post was first noticed by researchers at Cybernews.

Prime Day deals you can shop right now

Products available for purchase here through affiliate links are selected by our merchandising team. If you buy something through links on our site, Mashable may earn an affiliate commission.

"Xmas came early this year," user "ObamaCare" wrote on the forum. "I present to you a new rockyou2024 password list with over 9.9 billion passwords!"

RockYou2024 leaked password compilation

This gigantic list of leaked passwords known as RockYou2024 provides hackers with an important tool that can be utilized in a brute force attack. 

A brute force attack is a popular hacking method where the attacker guesses a user's password by trial-and-error. Hackers commonly use automated scripts when carrying out a brute force attack, which enables them to try out a slew of passwords within a short period of time. With a leaked password database this big, hackers have a nearly unlimited pool of passwords to try out. 

Mashable Light Speed
Want more out-of-this world tech, space and science stories?
Sign up for Mashable's weekly Light Speed newsletter.
By signing up you agree to our Terms of Use and Privacy Policy.
Thanks for signing up!

“In its essence, the RockYou2024 leak is a compilation of real-world passwords used by individuals all over the world," writes Cybernews' researchers. "Revealing that many passwords for threat actors substantially heightens the risk of credential stuffing attacks."

As Cybernews researchers point out, this list may very well be the largest password leak ever, beating the previous record holder known as RockYou2021, which had around 8.4 billion passwords.

In fact, the hacker forum user "ObamaCare" claims they used that older list and updated it with newer password leak data from over the past three years. As a result, 1.5 billion more passwords have been added to the previous compilation to create RockYou2024.

"I updated rockyou21 with collected new data from recent leaked databases in various forums over this and last years," wrote the hacker forum user while adding that they also included recent compromised passwords that they recently obtained themself.

The RockYou2024 leaked password list is new, so at the time of this writing, it's unclear if any private data has been compromised as a direct result of this compilation.

Anyone signed up to any service online should assume that a password that they use is on this list. Cybersecurity researchers recommend that users update their passwords and enable multi-factor authentication wherever possible.

Topics Cybersecurity


Recommended For You
Move over LastPass! Apple announces new password manager at WWDC 2024
MacBook showing Passwords app

'Futurama' Season 12 trailer promises intergalactic chaos
Professor Farnsworth and Bender from "Futurama."



Slew of Google Chrome security holes leaves billions of users impacted
Google Chrome

Trending on Mashable
NYT Connections today: See hints and answers for July 12
A phone displaying the New York Times game 'Connections.'

Wordle today: Here's the answer hints for July 12
a phone displaying Wordle

How streamer Pirate Software gained nearly two million subs in six months
pirate software in front of twitch surrounded by follower notifications

'The Acolyte' keeps referencing 'The Last Jedi' — here's why
The Stranger on the unknown planet.

NYT's The Mini crossword answers for July 12
Closeup view of crossword puzzle clues
The biggest stories of the day delivered to your inbox.
This newsletter may contain advertising, deals, or affiliate links. Subscribing to a newsletter indicates your consent to our Terms of Use and Privacy Policy. You may unsubscribe from the newsletters at any time.
Thanks for signing up. See you at your inbox!