HomeSecurityHacker sells 117 million LinkedIn user passwords on the Dark Web

Hacker sells 117 million LinkedIn user passwords on the Dark Web

Data from an earlier LinkedIn data breach has surfaced online, and a hacker known as Peace_of_mind (Peace) is selling it for 5 Bitcoin (≈ $2,200) on the Dark Web marketplace, TheRealDeal.

LinkedIn suffered a massive data breach in 2012, when hackers breached servers and stole some of its users' files. The hackers later posted 6.5 million of the stolen files online, complete with users' passwords in hashed form.

Hacker sells 117 million LinkedIn user passwords on the Dark Web

Peace claims this data is part of the 2012 breach. He claims to have data on 167,370,940 accounts, but said only about 117 million of them include hashed passwords. The last time LinkedIn disclosed its total user count, it said it had 433 million registered users.

Two websites that specialize in collecting data from online breaches, LeakedSource and Have I Been Pwned? analyzed the data.

Troy Hunt, the creator of Have I Been Pwned?, said on Twitter: "I confirm the alleged data breach of 167M LinkedIn records. It is *very* likely that this is true."

It later revealed that the data was indeed from the 2012 breach and warned that the passwords were encrypted with SHA1 without salting, meaning weak passwords could be easily cracked.

SHA1 is a strong encryption algorithm, but advances in modern computing power allow attackers to crack SHA1 password strings. Fraudsters cannot crack these strings instantly, but over time, all password hashes will be cracked. The simpler the password, the faster it is to crack.

linked-in-account

LeakedSource says they have access to all 167 million accounts, which they added to their service, so users can safely search and see if they were included in the breach .

Back in 2012, despite 6.5 million user details being leaked online, LinkedIn never confirmed how many users were affected, keeping a tight lid on it and people forgetting it happened.

If LinkedIn had shared the true impact of the data breach, users would have taken the necessary steps to secure accounts and avoid reusing their LinkedIn password for other accounts.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS