Get All Access for $5/mo

Over 10 Billion Passwords Have Been Exposed in the Largest Password Hack in History The data is thought to have been collected over the past two decades.

By Emily Rella Edited by Melissa Malamut

Key Takeaways

  • A text file called RockYou2024 was uploaded to the dark web on July 4, exposing over 10 billion unique passwords.
  • It marks the largest password leak in history.

Opinions expressed by Entrepreneur contributors are their own.

A massive hack occurred over the July 4th holiday when 10 billion unique passwords were exposed from users and customers across a slew of popular websites, including Ticketmaster and Santander.

The plain text file, called RockYou2024, leaked the passwords of customers all over the world. The data is thought to have been collected through a series of hacks over two decades.

Related: Ticketmaster Hack Affects Over 560 Million Customers

"In its essence, the RockYou2024 leak is a compilation of real-world passwords used by individuals all over the world. Revealing that many passwords for threat actors substantially heightens the risk of credential stuffing attacks," researchers for CyberNews said. "Threat actors could exploit the RockYou2024 password compilation to conduct brute-force attacks and gain unauthorized access to various online accounts used by individuals who employ passwords included in the dataset."

The CyberNews team noted the leak, combined with other breaches that exposed email addresses and phone numbers, could lead to "a cascade of data breaches, financial frauds, and identity thefts."

Bad actors could attempt attacks on anything from "internet-facing cameras and even industrial hardware," they added.

For example, if a hacker sees that your email address is associated with the password in the RockYou2024 file, it might check to see if you use the same password for your email address for another company leaked in a separate hack.

Though this hack is said to be the largest in history, it's not the first "RockYou" event.

Related: AT&T Customer Data Leaked to 'Dark Web,' Millions Affected

In 2021, RockYou2021 was published, containing an estimated 8.4 billion passwords. RockYou2024 is thought to include these passwords plus an additional 1.5 billion collected over the past three years. RockYou2021 was primarily composed of social media account passwords.

CyberNews recommends changing passwords used across multiple websites or accounts and enabling multi-factor authorization on any devices possible.

Emily Rella

Senior News Writer

Emily Rella is a Senior News Writer at Entrepreneur.com. Previously, she was an editor at Verizon Media. Her coverage spans features, business, lifestyle, tech, entertainment, and lifestyle. She is a 2015 graduate of Boston College and a Ridgefield, CT native. Find her on Twitter at @EmilyKRella.

Want to be an Entrepreneur Leadership Network contributor? Apply now to join.

Editor's Pick

Growing a Business

4 Ways I Grew My Business From Startup to 17 Years of Sustained Success

Whatever the future holds, remembering these four lessons will help sustain and scale your startup to a lasting legacy.

Side Hustle

This 20-Year-Old Student Started a Side Hustle With $400 — and It Earned $150,000 Over the Summer

Jacob Shaidle launched his barbecue cleaning business Shaidle Cleaning in 2021 when he was just 15.

Business News

Barbara Corcoran Says This Is the One Question to Ask Before Selling Your Home

Barbara Corcoran sold The Corcoran Group in 2001 for $66 million.

Business News

Google Says It Won't Follow Amazon's Lead With a Return-to-Office Mandate — Yet

In a town hall, Google leaders told staff the current hybrid plan will stay in place.

Business News

'Not a Big Deal': Barbara Corcoran Says the NAR Ruling Hasn't Had Much of an Impact So Far

The ruling removes the commission rate that home sellers are expected to pay.