A huge unencrypted database containing email addresses and passwords, as well as some credit card details, was found on a free hosting service. The service's administrator sent a copy of the database to Troy Hunt, a security researcher and creator of Have I been pwned, so that he could compare it with existing data and determine whether it was a new data breach. It is believed to be intended for a Credential stuffing attack.

Researcher Troy, judging by the file's format, believes it is a list that has been compiled from addresses from previous breaches. The most likely reason for the database being created is believed to be credential stuffing.
Credential stuffing is a type of attack where login credentials (usually usernames and passwords) from previous breaches are tested by automated programs against different services. For example, testing the 2016 Dailymotion to Google database leak is credential stuffing. Since many users use the same email and password combination for more than one online account, credential stuffing can compromise multiple accounts.
Troy, in a post yesterday, said he analyzed the database and concluded that 93% of the addresses were already in the Have I been pwnd. However, the remaining 7% that were not there corresponded to more than 2.5 million user combinations.
Also, after Troy's attempt to understand where this database comes from, he did not come to any conclusion, as there is no specific pattern. The addresses appear to have been compiled in random order.
Cybercriminals exchange databases of login credentials on a daily basis. So when a combination is leaked, there is a chance that it will end up in many different hands. For this reason, it is recommended to use long and complex access codes, but more importantly, use a different password for each online service.
