Observed Signal · Jun 17, 2026 · Data Breach · Source: t3n · Impact: 2/5 · Sentiment: Negative
124M Passwords Stolen in Stealer-Logs
HaveIBeenPwned has added a dataset containing 124 million stolen passwords and 56 million email addresses to its breach directory. According to the service, the credentials were harvested from infected end-user machines and aggregated in so‑called stealer‑logs created by infostealer malware, rather than leaked from a single major online provider. HaveIBeenPwned did not disclose how it obtained the dataset or whether the records are already circulating on darknet markets. The site allows users to search both email addresses and passwords to check for exposure; registration unlocks additional history and alerting features. Security best practices remain the same: immediately change exposed passwords and avoid reusing them across services.
Large-scale credential harvesting raises security and identity risks for users and increases exposure to account takeover and credential-stuffing attacks; relevant to identity and data-protection practices but not an industry-shifting platform policy.
Track TargetVideo Signals & Market Shifts in Real-Time
Polaris7 autonomous intelligence agents track regulatory filings, primary sources, executive changes, and deal flow 24/7. Create your free Explorer workspace to monitor these entities.
Key Takeaways & Evidence Grounding
- HaveIBeenPwned added 124 million stolen passwords to its password directory.
- HaveIBeenPwned added 56 million email addresses associated with those passwords.
- The data set originates from stealer-logs produced by infostealer malware on infected user devices, not from a single major online service breach.
- HaveIBeenPwned did not disclose how it obtained the records or whether they are circulating in the darknet.
- Users can search passwords and email addresses on HaveIBeenPwned and are advised to change exposed passwords and stop reusing them.
Connected Companies & Entities
2 Entities mappedOntology Mapping & Concepts
Related Market Signals & Shifts
Recent verified developments and strategic activity across this market segment.
Password-Stealing Malware Exposes 1,787 US Water Providers
New research from cybersecurity firm SpyCloud reveals that over a thousand U.S. water and wastewater providers are at risk due to password-stealing malware that compromised employee credentials and session tokens. The firm analyzed over 66,000 public-facing systems registered with the Environmental Protection Agency, identifying 1,787 organizations (nearly 20%) with stolen credentials, and at least 250 with credentials having potential access to operational networks. A case study of an unnamed metering tech provider found one infected device had leaked passwords for 167 utility companies. While this research did not link these exposures to the recent Iran-backed hacks, it underscores the vulnerability of critical infrastructure through infostealer malware and the trade of stolen credentials.
Instagram password-reset emails spark phishing fears
Over the weekend, millions of Instagram users received password-reset emails they did not initiate, prompting security experts to warn of potential phishing and fraud. Malwarebytes highlighted a purported dataset tied to around 17.5 million Instagram accounts that was offered for sale on the dark web, reporting that it could include usernames, email addresses, phone numbers, and some physical addresses. Instagram acknowledged the issue but denied a data breach or unauthorized access to accounts, saying users can ignore the emails and that passwords were not automatically changed. Security researchers caution that even without a breach, circulating data can fuel phishing attempts. Instagram advised a cautious approach and recommended steps to protect accounts: enable two-factor authentication, review logged-in devices in the Meta Accounts Center, consider changing passwords, and avoid clicking links in suspicious emails. Some observers noted the possibility that older datasets are resurfacing rather than a fresh incident.
LastPass Customer Data Stolen via Klue Breach
Password manager LastPass is handling a data breach after attackers accessed customer information by compromising a third‑party market intelligence platform, Klue. Klue detected unauthorized activity on 2026-06-12 and says attackers likely used old, compromised credentials for an integration service. Through that access, attackers viewed LastPass support tickets containing customer names, phone numbers, email addresses, home addresses, support-case details and sales-relevant information; payment data included in support tickets may also have been exposed. LastPass says its internal systems and user vaults were not compromised, and it is notifying affected users by email. Actions taken include suspending Klue employees’ access to LastPass data, rotating API access tokens, and planning additional protections. Users are advised to monitor payment activity and consider changing associated email addresses to reduce phishing risk.
Track Real-Time Market Signals & Shifts
Set up custom watchlists to receive automated, evidence-grounded executive digests whenever material signals or shifts occur across your tracked landscape.
