{"id":345617,"date":"2025-12-13T15:43:12","date_gmt":"2025-12-13T15:43:12","guid":{"rendered":"https:\/\/www.newsbeep.com\/au\/345617\/"},"modified":"2025-12-13T15:43:12","modified_gmt":"2025-12-13T15:43:12","slug":"fbi-confirms-630-million-stolen-passwords-how-to-check-yours-now","status":"publish","type":"post","link":"https:\/\/www.newsbeep.com\/au\/345617\/","title":{"rendered":"FBI Confirms 630 Million Stolen Passwords \u2014 How To Check Yours Now"},"content":{"rendered":"<p><img decoding=\"async\" class=\" top-image\" src=\"https:\/\/www.newsbeep.com\/au\/wp-content\/uploads\/2025\/12\/1765640592_847_0x0.jpg\" alt=\"FBI website through a magnifying glass\" data-height=\"2299\" data-width=\"3456\" fetchpriority=\"high\" style=\"position:absolute;top:0\"\/><\/p>\n<p>FBI reveals 630 million stolen passwords.<\/p>\n<p>getty<\/p>\n<p>Just when you thought things couldn\u2019t get any worse in terms of cybersecurity bad news this week, the FBI has revealed a staggering database of 630 million compromised passwords from multiple devices seized from a hacker. Here\u2019s what to know and how to check if your passwords are on the danger list. <\/p>\n<p><a class=\"embed-base color-body color-body-border link-embed embed-1\" href=\"https:\/\/www.forbes.com\/sites\/daveywinder\/2025\/12\/12\/microsoft-warning---act-rapidly-and-change-passwords-as-attacks-strike\/\" target=\"_blank\" aria-label=\"Microsoft Worm Attack Warning \u2014 Act Rapidly And Change Passwords Now\" data-ga-track=\"forbesEmbedly:https:\/\/www.forbes.com\/sites\/daveywinder\/2025\/12\/12\/microsoft-warning---act-rapidly-and-change-passwords-as-attacks-strike\/\" rel=\"nofollow noopener\">ForbesMicrosoft Worm Attack Warning \u2014 Act Rapidly And Change Passwords NowBy Davey Winder<\/a>FBI Finds 630 Million Stolen Passwords On Seized Hackers\u2019 Devices<\/p>\n<p>Troy Hunt, the creator of the ingenious Have I Been Pwned and Pwned Passwords services, has confirmed that the Federal Bureau of Investigation has handed over a staggering list of 630 million <a class=\"color-link\" href=\"https:\/\/www.forbes.com\/sites\/daveywinder\/2025\/11\/14\/800-million-compromised-passwords---what-you-need-to-know\/\" data-ga-track=\"InternalLink:https:\/\/www.forbes.com\/sites\/daveywinder\/2025\/11\/14\/800-million-compromised-passwords---what-you-need-to-know\/\" target=\"_self\" aria-label=\"compromised passwords\" rel=\"nofollow noopener\">compromised passwords<\/a> to add to the HIBP database of 17 billion compromised accounts. The FBI has been sending Hunt compromised passwords for four years, as uncovered during the course of cybercrime investigations, but what\u2019s concerning and almost unbelievable in equal measure is that the latest haul is from a single hacker. <\/p>\n<p>\u201cThis latest corpus of data came to us as a result of the FBI seizing multiple devices belonging to a suspect,\u201d <a class=\"color-link\" href=\"https:\/\/www.troyhunt.com\/processing-630-million-more-pwned-passwords-courtesy-of-the-fbi\/\" target=\"_blank\" rel=\"nofollow noopener noreferrer\" data-ga-track=\"ExternalLink:https:\/\/www.troyhunt.com\/processing-630-million-more-pwned-passwords-courtesy-of-the-fbi\/\" aria-label=\"Hunt said\">Hunt said<\/a>, adding that \u201dthe sheer scope of cybercrime can be hard to fathom, even when you live and breathe it every day.\u201d To which I can only say, indeed it is. <\/p>\n<p>It seems that the hacked passwords have come from open and dark web marketplaces, Telegram channels and, inevitably, <a class=\"color-link\" href=\"https:\/\/www.forbes.com\/sites\/daveywinder\/2025\/08\/01\/information-stealing-machine-behind-theft-of-18-billion-credentials\/\" data-ga-track=\"InternalLink:https:\/\/www.forbes.com\/sites\/daveywinder\/2025\/08\/01\/information-stealing-machine-behind-theft-of-18-billion-credentials\/\" target=\"_self\" aria-label=\"infostealer attacks\" rel=\"nofollow noopener\">infostealer attacks<\/a>. <\/p>\n<p>All of which means, of course, that not all of the 630 million credentials handed over to Hunt are going to be fresh to market, as it were. And, indeed, that appears to be the case following an initial HIBP team analysis: \u201cWe hadn&#8217;t seen about 7.4% of them in HIBP before,\u201d Hunt confirmed, \u201cwhich might sound small, but that&#8217;s 46 million vulnerable passwords we weren&#8217;t giving people using the service the opportunity to block.\u201d<\/p>\n<p><a class=\"embed-base color-body color-body-border link-embed embed-2\" href=\"https:\/\/www.forbes.com\/sites\/daveywinder\/2025\/12\/12\/lastpass-data-breach---insufficient-security-exposed-16-million-users\/\" target=\"_blank\" aria-label=\"LastPass Data Breach \u2014 Insufficient Security Exposed 1.6 Million Users\" data-ga-track=\"forbesEmbedly:https:\/\/www.forbes.com\/sites\/daveywinder\/2025\/12\/12\/lastpass-data-breach---insufficient-security-exposed-16-million-users\/\" rel=\"nofollow noopener\">ForbesLastPass Data Breach \u2014 Insufficient Security Exposed 1.6 Million UsersBy Davey Winder<\/a>FBI Stolen Credentials Handover: How To Check If Your Passwords Are On The List<\/p>\n<p>The good news is that all of the stolen credentials, all those compromised passwords, are now searchable from a single location, which leaves you a second or two away from discovering if any of yours are included.<\/p>\n<p>Head to the <a class=\"color-link\" href=\" The good news is that all of the stolen credentials, all those compromised passwords, are now searchable from a single location, which leaves you a second or two away from discovering if any of yours are included.   Head to the Pwned Passwords https:\/\/haveibeenpwned.com\/Passwords service, and enter your password. Don\u2019t worry, it\u2019s perfectly safe and won\u2019t put your passwords in any danger, just the opposite in fact. \u201cNo password is stored next to any personally identifiable data such as an email address,\u201d Hunt said, \u201cand every password is SHA-1 hashed.\u201d\" target=\"_blank\" rel=\"nofollow noopener noreferrer\" data-ga-track=\"ExternalLink: The good news is that all of the stolen credentials, all those compromised passwords, are now searchable from a single location, which leaves you a second or two away from discovering if any of yours are included.   Head to the Pwned Passwords https:\/\/haveibeenpwned.com\/Passwords service, and enter your password. Don\u2019t worry, it\u2019s perfectly safe and won\u2019t put your passwords in any danger, just the opposite in fact. \u201cNo password is stored next to any personally identifiable data such as an email address,\u201d Hunt said, \u201cand every password is SHA-1 hashed.\u201d\" aria-label=\"Pwned Passwords\">Pwned Passwords<\/a> service, and enter your password. Don\u2019t worry, it\u2019s perfectly safe and won\u2019t put your passwords in any danger, just the opposite in fact. \u201cNo password is stored next to any personally identifiable data such as an email address,\u201d Hunt said, \u201cand every password is SHA-1 hashed.\u201d<\/p>\n<p>Most importantly, do it now so you can change any passwords that are already compromised before your accounts fall victim to credential-stuffing attacks. I would also recommend that you use a password manager, despite <a class=\"color-link\" href=\"https:\/\/www.forbes.com\/sites\/daveywinder\/2025\/12\/12\/lastpass-data-breach---insufficient-security-exposed-16-million-users\/\" data-ga-track=\"InternalLink:https:\/\/www.forbes.com\/sites\/daveywinder\/2025\/12\/12\/lastpass-data-breach---insufficient-security-exposed-16-million-users\/\" target=\"_self\" aria-label=\"some having suffered breaches\" rel=\"nofollow noopener\">some having suffered breaches<\/a>, as it is safer than reusing a handful of easily remembered ones. Oh, and enable passkeys on any accounts that support them. Then there\u2019s the small matter of <a class=\"color-link\" href=\"https:\/\/www.forbes.com\/sites\/daveywinder\/2025\/07\/28\/new-fbi-warning---windows-and-linux-users-must-apply-2fa-now\/\" data-ga-track=\"InternalLink:https:\/\/www.forbes.com\/sites\/daveywinder\/2025\/07\/28\/new-fbi-warning---windows-and-linux-users-must-apply-2fa-now\/\" target=\"_self\" aria-label=\"activating two-factor authentication\" rel=\"nofollow noopener\">activating two-factor authentication<\/a> on all your accounts as well. Stay safe, even when the FBI finds the next big stolen password haul. It\u2019s only a matter of time. <\/p>\n<p><a class=\"embed-base color-body color-body-border link-embed embed-3\" href=\"https:\/\/www.forbes.com\/sites\/daveywinder\/2025\/12\/04\/has-your-gmail-password-been-hacked-check-now-heres-how\/\" target=\"_blank\" aria-label=\"Has Your Gmail Password Been Hacked? Check Now, Here\u2019s How\" data-ga-track=\"forbesEmbedly:https:\/\/www.forbes.com\/sites\/daveywinder\/2025\/12\/04\/has-your-gmail-password-been-hacked-check-now-heres-how\/\" rel=\"nofollow noopener\">ForbesHas Your Gmail Password Been Hacked? Check Now, Here\u2019s HowBy Davey Winder<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"FBI reveals 630 million stolen passwords. getty Just when you thought things couldn\u2019t get any worse in terms&hellip;\n","protected":false},"author":2,"featured_media":345618,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[6],"tags":[64,63,191200,191195,191194,191198,191199,90016,191197,191202,191201,191196,105],"class_list":["post-345617","post","type-post","status-publish","format-standard","has-post-thumbnail","category-technology","tag-au","tag-australia","tag-feds","tag-have-i-been-pwned","tag-hibp","tag-my-password-has-been-compromised","tag-my-password-has-been-hacked","tag-password","tag-password-hacked","tag-password-hacking","tag-password-theft","tag-stolen-password","tag-technology"],"_links":{"self":[{"href":"https:\/\/www.newsbeep.com\/au\/wp-json\/wp\/v2\/posts\/345617","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.newsbeep.com\/au\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.newsbeep.com\/au\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/au\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/au\/wp-json\/wp\/v2\/comments?post=345617"}],"version-history":[{"count":0,"href":"https:\/\/www.newsbeep.com\/au\/wp-json\/wp\/v2\/posts\/345617\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/au\/wp-json\/wp\/v2\/media\/345618"}],"wp:attachment":[{"href":"https:\/\/www.newsbeep.com\/au\/wp-json\/wp\/v2\/media?parent=345617"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.newsbeep.com\/au\/wp-json\/wp\/v2\/categories?post=345617"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.newsbeep.com\/au\/wp-json\/wp\/v2\/tags?post=345617"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}