[ THREAT ARCHIVE :: 2019 ]
EXPOSURE SCALE: 773,000,000 RECORDS
Collection #1 Combolist — What Was Leaked & How to Check If You're In It
Discovered in January 2019 hosted on MEGA cloud storage, Collection #1 contained 87 gigabytes of de-duplicated credential archives from over 2,000 individual hacked databases.
INCIDENT YEAR: 2019
ATTACK VECTOR: Aggregated De-Hashed Credential Dumps
SEVERITY RATING: HIGH
> COMPROMISED DATA ATTRIBUTES IN THIS BREACH:
[✓] Email Addresses
[✓] Plaintext Passwords
[✓] Username Pairings
> TECHNICAL POST-MORTEM & VECTOR ANALYSIS
- Consisted of 1,160,253,228 unique combinations of email addresses and passwords.
- 21,222,973 passwords in the dump were previously unseen in public hash databases.
> VERIFY IF YOUR CREDENTIALS APPEARED IN THIS DUMP
Query the DARKLEDGER multi-source engine to check if your email, username, or phone number was indexed in the Collection #1 Combolist dataset.
> STEP-BY-STEP REMEDIATION PLAYBOOK
- Check if your email exists in Collection #1 using our free search below.
- Check if any reused passwords from 2019 or earlier are still in use.
> FREQUENTLY ASKED QUESTIONS ABOUT THIS BREACH
Q: Was my password cracked in Collection #1?
If your account was in Collection #1, your password was stored in plain text and circulated publicly across underground forums.