Billions of compromised passwords in circulation – what now?

Picture of Silvio Mazenauer
Silvio Mazenauer
Billions of compromised credentials are circulating on the internet. Learn how to better protect passwords, email accounts, and corporate access from abuse with simple measures.
Compromised passwords and protection through 2FA, password managers, and passkeys

Billions of compromised credentials are circulating on the internet. They originate from data leaks, phishing attacks, infostealer malware, and other attacks, and are sometimes combined into massive data collections.

In 2025, a particular amount of attention was received by a collection of around 16 billion login records. However, this was neither a single new attack nor 16 billion different affected individuals. The data came from various sources and also contained duplicates.

For users and companies, the exact number is secondary anyway. The decisive factor is: Stolen credentials can still be used for attacks – especially when passwords are reused.

Where do the compromised credentials originate?

Such collections of passwords and credentials usually do not come from a single major hacker attack. Instead, data from various sources is collected and later combined.

Typical sources are:

  • Data leaks at online services and companies
  • Phishing attacks on users
  • Infostealer malware on computers and other end devices
  • stolen browser and login credentials
  • older password collections and databases

Particularly problematic are so-called Infostealer. Among other things, these malicious programs attempt to read access credentials stored in the browser or on the device and transmit them to attackers.

Why reused passwords are so dangerous

A stolen password does not only have to be dangerous for the service originally affected.

Anyone who uses the same password for multiple accounts may turn a single data breach into a problem for numerous other logins.

Attackers can automatically try known combinations of email address, username, and password on other services. This attack method is called Credential Stuffing referred to as.

If, for example, the same password works for the online shop, the cloud service, and the email account, a single compromised access point can have far-reaching consequences.

Why the email account should be particularly protected

The email account is one of the most important digital access points of all. It is used to reset passwords, send confirmations, and exchange both business and personal information.

A compromised email account can, among other things:

  • enable access to additional user accounts,
  • disclose confidential messages and documents,
  • used for phishing and identity theft,
  • send fake messages on behalf of the affected person.

Particularly for companies, this can quickly become a significant security problem. In addition to secure access data, spam, phishing, and malware protection therefore also play an important role. You can find out more about this at our Email security solutions.

What you should do now, specifically

You don't have to wait for the next report of a major data breach. With a few basic measures, the risk of compromised accounts can be significantly reduced.

1. Use a separate password for each service

Never use the same password for multiple important accounts. Email, hosting, cloud services, payment providers, and administrative access in particular should each have their own strong password.

You can create a strong password, for example, with our free Password generator create.

2. Use password manager

A password manager can generate long and unique passwords and manage them securely. This means you do not have to remember a complex password for every service.

3. Enable two-factor authentication

Enable two-factor or multi-factor authentication if possible. In addition to the password, another factor is then required for login.

Because of this, a stolen password alone is often no longer enough for an attacker to gain access to the account.

4. Check if your own email address appears in a data leak

The service Have I Been Pwned enables checking whether an email address was found in known data breaches.

A match does not automatically mean that a current password is known. However, it is a clear reason to check the affected accounts and access credentials.

5. Use passkeys when they are offered

More and more services are supporting so-called Passkeys. In the process, the traditional password-based login is replaced by a cryptographic authentication method.

Passkeys are significantly more robust, particularly against classic phishing attacks, and avoid problems such as weak or reused passwords.

Also secure hosting and administration access

For companies, not only personal user accounts are relevant. Access to WordPress, hosting control panels, domain management, FTP/SFTP, and business email accounts should also be given special protection.

Administrator accounts should only be given to individuals who actually need them. Use individual credentials, enable available multi-factor authentication, and remove user accounts that are no longer needed.

Conclusion: A password alone is no longer enough today

Billions of compromised access credentials show how important a well-thought-out security concept has become. The crucial factor is not so much the spectacular number of a single data discovery as the proper handling of one's own access credentials.

Unique passwords, a password manager, multi-factor authentication, and modern methods such as passkeys significantly complicate the misuse of stolen credentials.

For companies, an additional layer comes into play: hosting, websites, and email systems must also be properly secured and continuously maintained. Security is therefore not a one-time setup, but an ongoing process.

Share this post:

You might also be interested in this

Cookie Consent with Real Cookie Banner