16 Billion Passwords Exposed? Not Quite.

2025-08-17
16 Billion Passwords Exposed? Not Quite.

A recent headline claiming 16 billion passwords were exposed in a record-breaking breach sparked widespread concern. Security expert Troy Hunt investigated and found the reality far less alarming. The data wasn't from a single breach, but aggregated from multiple infostealer datasets. Significant duplication existed, with most email/password combinations already in the Have I Been Pwned (HIBP) database. Only 4.4 million unique email addresses were newly added. The sensationalized headline misrepresented the situation, highlighting the need for a more nuanced understanding of data breaches.

Read more
Tech

Have I Been Pwned: The Next Generation

2025-05-19
Have I Been Pwned: The Next Generation

After years of development, the hugely popular data breach search engine, Have I Been Pwned (HIBP), has launched a completely redesigned website. This massive overhaul includes a rebuilt website architecture, enhanced search functionality (complete with celebratory confetti!), dedicated breach pages with actionable advice, a unified dashboard, and even a brand new merchandise store! The API remains unchanged, ensuring backwards compatibility. AI tools significantly assisted the development process. The result is a faster, more user-friendly experience while retaining HIBP's signature straightforward approach to providing crucial data breach information.

Read more

Have I Been Pwned Speeds Up Dramatically with Cloudflare Edge Caching

2025-04-23
Have I Been Pwned Speeds Up Dramatically with Cloudflare Edge Caching

Have I Been Pwned (HIBP) dramatically improved its speed and availability by caching data on Cloudflare's global edge network. Previously, each query involved a long trip to an Azure function, but now data resides close to users. This reduces latency, boosts availability, and saves costs. While new data updates clear the cache causing temporary slowdowns, the overall architecture vastly optimizes HIBP's performance, enabling it to handle billions of queries.

Read more
Tech caching

Security Expert Troy Hunt Falls Victim to Mailchimp Phishing Attack

2025-03-25
Security Expert Troy Hunt Falls Victim to Mailchimp Phishing Attack

Security expert Troy Hunt fell victim to a sophisticated phishing attack targeting his Mailchimp account. The attacker successfully gained access, exporting approximately 16,000 subscriber records containing email addresses, subscription details, IP addresses, and geolocation data. Despite immediately changing his password and contacting Mailchimp, Hunt expressed frustration at his own lapse in judgment and apologized to affected subscribers. The incident serves as a stark reminder that even security experts are vulnerable to phishing, highlighting the importance of robust multi-factor authentication and heightened security awareness.

Read more
Tech