
Breach registry
ExploitIn Data Breach
Exploit.In
What was exposed, when it happened, and which databases confirm it.
- accounts
- 800,538,221
- Breached
- October 13, 2016
- Last Update
- May 6, 2017
Were you caught in this breach?
Search your email, phone number or username against every record CheckLeaked indexes.
What happened
In late 2016, a huge list of email address and password pairs appeared in a "combo list" referred to as "Exploit.In". The list contained 593 million unique email addresses, many with multiple different passwords hacked from various online systems. The list was broadly circulated and used for "credential stuffing", that is attackers employ it in an attempt to identify other online systems where the account owner had reused their password. For detailed background on this incident, read Password reuse, credential stuffing and another billion records in Have I Been Pwned.
Compromised Info
- Email addresses
- Passwords
Attestation
Four independent databases catalog this breach and they do not always agree. Each lane below is one source’s own count.
207,111,102 accounts DEHASHED reports beyond HIBP
Sources & Link Methods
- Dehashed
- HIBP
FAQ
What was leaked in the ExploitIn breach?
The ExploitIn breach exposed: Email addresses and Passwords.
When did the ExploitIn breach happen?
The ExploitIn breach was disclosed on October 13, 2016 and affected 593,427,119 records.
Am I affected by the ExploitIn breach?
Search your email, phone or username at checkleaked.cc to find out whether your data appears in the ExploitIn leak.