Just months after a massive breach that exposed more than 184 million passwords and logins, another major data breach has emerged, this time affecting 183 million email addresses and passwords from an April 2025 incident.
Security researcher Troy Hunt, creator of Have I Been Pwned (HIBP), described the platform’s latest batch of data as a combination of “thief logs and credential stuffing lists.” The exposed information includes website URLs, email addresses, and confirmed Gmail login details.
Have I Been Pwned remains one of the most reliable free tools for checking if personal information has appeared in data breaches. The October 21 update, which lists 183 million compromised accounts, quickly caught the attention of cybersecurity experts and users around the world.
According to Hunt, the data originated from Synthient, a threat intelligence company that had been monitoring information theft platforms for almost a year. The trove, totaling about 3.5 terabytes and 23 billion rows, included website addresses, email addresses and passwords.
“Someone who logs into Gmail ends up with their email address and password captured on Gmail.com,” Hunt explained.
Their analysis showed that around 92% of the logs had appeared in previous breaches, particularly the ALIEN TXTBASE thief logs. Still, about 8% were new, representing more than 16 million never-before-seen email addresses.
To confirm authenticity, HIBP contacted affected subscribers. “One of the respondents was already concerned that there might be something wrong with their Gmail account,” Hunt said, adding that the user confirmed that the password provided was still correct.
Anyone concerned that their information may be compromised should reportedly visit Have I Been Pwned to see if their email or passwords are included in the breach. If so, cybersecurity experts recommend changing those passwords immediately and avoiding reusing passwords across different accounts.
Google has not yet commented on the matter.
(Forbes)
READ ALSO TOP STORIES OF Newslodge
