Digital transformation

Over 19 billion passwords have been leaked: What can you do to protect yourself?

Phan Van Hoa May 6, 2025 06:00

Over 19 billion leaked passwords are circulating on the internet, becoming a massive data repository for hackers to exploit. This is an unprecedented and serious threat, raising concerns about a wave of large-scale global cyberattacks.

In this era of rapid digitalization, where data leaks and cyberattacks are increasing at an alarming rate, protecting personal accounts is no longer an option, but a pressing need to ensure information security and privacy.

In just the last few months, cybersecurity experts have witnessed an exponential increase in the number of leaked passwords, from 800 million to 1.7 billion and quickly reaching 2.1 billion.

Ảnh minh họa
Illustrative image.

The cause of this increase has been identified as stemming from malware attacks aimed at stealing information, which are escalating on an unprecedented scale.

However, a newly published report has overshadowed all of the aforementioned staggering figures. A research team from Cybernews has just revealed a shocking analysis, according to which over 19 billion passwords have been leaked – specifically, 19,030,305,929 passwords are currently being shared publicly on the dark web and cybercrime forums, readily available for anyone to exploit.

Imagine a massive “password vault” containing information from over 200 data breaches in just 12 months, starting from April 2024, all paired with valid email addresses—creating a goldmine for large-scale automated attacks.

More importantly, this dataset only includes passwords that have been made public, meaning that billions more passwords are still being shared secretly or stored in private data repositories of hacker groups.

When laziness becomes an "open door" for hackers.

Of the more than 19 billion leaked passwords, only 6% were unique, equivalent to approximately 1.14 billion. This means that the remaining 94% of passwords were reused across multiple accounts and services.

This is the "fatal weakness" that makes credential stuffing attacks so incredibly effective.

Even more concerning, 42% of the leaked passwords were only 8 to 10 characters long, making it easier than ever to crack them using automated brute-force methods.

Ảnh minh họa0
Users should avoid using common, easily guessable passwords such as "123456" or their birth dates. Photo: Internet.

Furthermore, 27% of passwords consist only of lowercase letters and numbers, with no special characters or uppercase letters, significantly reducing their security.

Security expert Neringa Macijauskaitė from Cybernews stated: "Using default passwords remains one of the most dangerous and common habits in any data breach." Specifically, data analysis shows that there were 53 million instances of using 'admin' and 56 million instances of using 'password' as the primary password.

"Hackers are very keen to try these common passwords first, making them some of the least secure options," Macijauskaitė warned.

Essential advice: Never reuse passwords.

Macijauskaitė also issued a crucial warning: never reuse the same password for multiple accounts. Because if just one of your services is compromised, your entire personal account ecosystem could be breached in a domino effect.

Ms. Macijauskaitė stated: “Even before any attacks occur, hackers are constantly collecting common password patterns, leaked login credentials, and cracked hash strings. This data is being used to carry out increasingly sophisticated attack campaigns that bypass traditional defenses.”

How can I protect my personal accounts from cyber threats?

In the context of increasingly sophisticated cybercrime, protecting personal accounts is more important than ever. Cybersecurity experts recommend that users take the following steps to enhance security:

- Create strong, unique passwords for each account:Avoid using common, easily guessable passwords like “123456” or your birth date. Each account should have a unique password, including a combination of uppercase letters, lowercase letters, numbers, and special characters to increase complexity.

- Enable two-factor authentication (2FA):This is an additional layer of security, requiring users to verify their identity with a temporary code sent via phone, email, or authentication app. This helps prevent unauthorized access even if a malicious actor obtains your password.

Ảnh minh họa01
Create a strong password that includes a combination of uppercase letters, lowercase letters, numbers, and special characters to increase its complexity. (Image: Internet)

- Use a password manager:Password management applications like 1Password, LastPass, or Bitwarden can generate and store hundreds of strong, random passwords, saving you the trouble of memorizing each one. They also help check if your passwords have been leaked.

Be cautious of suspicious links and requests:Do not click on links in emails, text messages, or social media posts if you are unsure of their source. Absolutely do not provide login information through suspicious forms, even if they appear to come from a bank, a familiar service, or a relative.

Implementing these simple yet effective measures can help you avoid many potential security risks and keep your digital identity safe in the online environment.

While the fact that over 19 billion passwords have been leaked sounds alarming, it's not the end of personal security. By proactively implementing security measures today, you can minimize risks and protect yourself against increasingly sophisticated cyberattacks.

Source: Forbes
Copy Link
0 0 0
x
Over 19 billion passwords have been leaked: What can you do to protect yourself?
Google News
POWERED BYFREECMS- A PRODUCT OFNEKO