{"id":347798,"date":"2025-12-14T16:39:08","date_gmt":"2025-12-14T16:39:08","guid":{"rendered":"https:\/\/www.newsbeep.com\/au\/347798\/"},"modified":"2025-12-14T16:39:08","modified_gmt":"2025-12-14T16:39:08","slug":"fbi-confirms-630-million-stolen-passwords-how-to-check-yours-now-2","status":"publish","type":"post","link":"https:\/\/www.newsbeep.com\/au\/347798\/","title":{"rendered":"FBI Confirms 630 Million Stolen Passwords \u2014 How To Check Yours Now"},"content":{"rendered":"<p><img decoding=\"async\" class=\" top-image\" src=\"https:\/\/www.newsbeep.com\/au\/wp-content\/uploads\/2025\/12\/1765640592_847_0x0.jpg\" alt=\"FBI website through a magnifying glass\" data-height=\"2299\" data-width=\"3456\" fetchpriority=\"high\" style=\"position:absolute;top:0\"\/><\/p>\n<p>FBI reveals 630 million stolen passwords.<\/p>\n<p>getty<\/p>\n<p>Updated December 14 with password manager usage advice following reports of a LastPass data breach caused by security failures and a no password required attack confirmed by Google, alongside the original reporting of the 630 million passwords revealed by the FBI following device seizures from a single hacker.<\/p>\n<p>Just when you thought things couldn\u2019t get any worse in terms of cybersecurity bad news this week, the FBI has revealed a staggering database of 630 million compromised passwords from multiple devices seized from a hacker. Here\u2019s what to know and how to check if your passwords are on the danger list. <\/p>\n<p><a class=\"embed-base color-body color-body-border link-embed embed-1\" href=\"https:\/\/www.forbes.com\/sites\/daveywinder\/2025\/12\/12\/microsoft-warning---act-rapidly-and-change-passwords-as-attacks-strike\/\" target=\"_blank\" aria-label=\"Microsoft Worm Attack Warning \u2014 Act Rapidly And Change Passwords Now\" data-ga-track=\"forbesEmbedly:https:\/\/www.forbes.com\/sites\/daveywinder\/2025\/12\/12\/microsoft-warning---act-rapidly-and-change-passwords-as-attacks-strike\/\" rel=\"nofollow noopener\">ForbesMicrosoft Worm Attack Warning \u2014 Act Rapidly And Change Passwords NowBy Davey Winder<\/a>FBI Finds 630 Million Stolen Passwords On Seized Hackers\u2019 Devices<\/p>\n<p>Troy Hunt, the creator of the ingenious Have I Been Pwned and Pwned Passwords services, has confirmed that the Federal Bureau of Investigation has handed over a staggering list of 630 million <a class=\"color-link\" href=\"https:\/\/www.forbes.com\/sites\/daveywinder\/2025\/11\/14\/800-million-compromised-passwords---what-you-need-to-know\/\" data-ga-track=\"InternalLink:https:\/\/www.forbes.com\/sites\/daveywinder\/2025\/11\/14\/800-million-compromised-passwords---what-you-need-to-know\/\" target=\"_self\" aria-label=\"compromised passwords\" rel=\"nofollow noopener\">compromised passwords<\/a> to add to the HIBP database of 17 billion compromised accounts. The FBI has been sending Hunt compromised passwords for four years, as uncovered during the course of cybercrime investigations, but what\u2019s concerning and almost unbelievable in equal measure is that the latest haul is from a single hacker. <\/p>\n<p>\u201cThis latest corpus of data came to us as a result of the FBI seizing multiple devices belonging to a suspect,\u201d <a class=\"color-link\" href=\"https:\/\/www.troyhunt.com\/processing-630-million-more-pwned-passwords-courtesy-of-the-fbi\/\" target=\"_blank\" rel=\"nofollow noopener noreferrer\" data-ga-track=\"ExternalLink:https:\/\/www.troyhunt.com\/processing-630-million-more-pwned-passwords-courtesy-of-the-fbi\/\" aria-label=\"Hunt said\">Hunt said<\/a>, adding that \u201dthe sheer scope of cybercrime can be hard to fathom, even when you live and breathe it every day.\u201d To which I can only say, indeed it is. <\/p>\n<p>It seems that the hacked passwords have come from open and dark web marketplaces, Telegram channels and, inevitably, <a class=\"color-link\" href=\"https:\/\/www.forbes.com\/sites\/daveywinder\/2025\/08\/01\/information-stealing-machine-behind-theft-of-18-billion-credentials\/\" data-ga-track=\"InternalLink:https:\/\/www.forbes.com\/sites\/daveywinder\/2025\/08\/01\/information-stealing-machine-behind-theft-of-18-billion-credentials\/\" target=\"_self\" aria-label=\"infostealer attacks\" rel=\"nofollow noopener\">infostealer attacks<\/a>. <\/p>\n<p>All of which means, of course, that not all of the 630 million credentials handed over to Hunt are going to be fresh to market, as it were. And, indeed, that appears to be the case following an initial HIBP team analysis: \u201cWe hadn&#8217;t seen about 7.4% of them in HIBP before,\u201d Hunt confirmed, \u201cwhich might sound small, but that&#8217;s 46 million vulnerable passwords we weren&#8217;t giving people using the service the opportunity to block.\u201d<\/p>\n<p><a class=\"embed-base color-body color-body-border link-embed embed-4\" href=\"https:\/\/www.forbes.com\/sites\/daveywinder\/2025\/12\/14\/41-microsoft-zero-days---now-millions-of-users-face-update-choice\/\" target=\"_blank\" aria-label=\"41 Microsoft Zero-Days \u2014 Now Millions Of Users Face Update Choice\" data-ga-track=\"forbesEmbedly:https:\/\/www.forbes.com\/sites\/daveywinder\/2025\/12\/14\/41-microsoft-zero-days---now-millions-of-users-face-update-choice\/\" rel=\"nofollow noopener\">Forbes41 Microsoft Zero-Days \u2014 Now Millions Of Users Face Update ChoiceBy Davey Winder<\/a>FBI Stolen Credentials Handover: How To Check If Your Passwords Are On The List<\/p>\n<p>The good news is that all of the stolen credentials, all those compromised passwords, are now searchable from a single location, which leaves you a second or two away from discovering if any of yours are included.<\/p>\n<p>Head to the <a class=\"color-link\" href=\" The good news is that all of the stolen credentials, all those compromised passwords, are now searchable from a single location, which leaves you a second or two away from discovering if any of yours are included.   Head to the Pwned Passwords https:\/\/haveibeenpwned.com\/Passwords service, and enter your password. Don\u2019t worry, it\u2019s perfectly safe and won\u2019t put your passwords in any danger, just the opposite in fact. \u201cNo password is stored next to any personally identifiable data such as an email address,\u201d Hunt said, \u201cand every password is SHA-1 hashed.\u201d\" target=\"_blank\" rel=\"nofollow noopener noreferrer\" data-ga-track=\"ExternalLink: The good news is that all of the stolen credentials, all those compromised passwords, are now searchable from a single location, which leaves you a second or two away from discovering if any of yours are included.   Head to the Pwned Passwords https:\/\/haveibeenpwned.com\/Passwords service, and enter your password. Don\u2019t worry, it\u2019s perfectly safe and won\u2019t put your passwords in any danger, just the opposite in fact. \u201cNo password is stored next to any personally identifiable data such as an email address,\u201d Hunt said, \u201cand every password is SHA-1 hashed.\u201d\" aria-label=\"Pwned Passwords\">Pwned Passwords<\/a> service, and enter your password. Don\u2019t worry, it\u2019s perfectly safe and won\u2019t put your passwords in any danger, just the opposite in fact. \u201cNo password is stored next to any personally identifiable data such as an email address,\u201d Hunt said, \u201cand every password is SHA-1 hashed.\u201d<\/p>\n<p>Most importantly, do it now so you can change any passwords that are already compromised before your accounts fall victim to credential-stuffing attacks. I would also recommend that you use a password manager. Oh, and enable passkeys on any accounts that support them. Then there\u2019s the small matter of <a class=\"color-link\" href=\"https:\/\/www.forbes.com\/sites\/daveywinder\/2025\/07\/28\/new-fbi-warning---windows-and-linux-users-must-apply-2fa-now\/\" data-ga-track=\"InternalLink:https:\/\/www.forbes.com\/sites\/daveywinder\/2025\/07\/28\/new-fbi-warning---windows-and-linux-users-must-apply-2fa-now\/\" target=\"_self\" aria-label=\"activating two-factor authentication\" rel=\"nofollow noopener\">activating two-factor authentication<\/a> on all your accounts as well. Stay safe, even when the FBI finds the next big stolen password haul. It\u2019s only a matter of time. <\/p>\n<p><a class=\"embed-base color-body color-body-border link-embed embed-3\" href=\"https:\/\/www.forbes.com\/sites\/daveywinder\/2025\/12\/04\/has-your-gmail-password-been-hacked-check-now-heres-how\/\" target=\"_blank\" aria-label=\"Has Your Gmail Password Been Hacked? Check Now, Here\u2019s How\" data-ga-track=\"forbesEmbedly:https:\/\/www.forbes.com\/sites\/daveywinder\/2025\/12\/04\/has-your-gmail-password-been-hacked-check-now-heres-how\/\" rel=\"nofollow noopener\">ForbesHas Your Gmail Password Been Hacked? Check Now, Here\u2019s HowBy Davey Winder<\/a>Don\u2019t Ignore This FBI Discovery \u2014 Use A Password Manager Now<\/p>\n<p>OK, so I\u2019ve already said you should use a password manager, but is that safe? It\u2019s a question I get asked all the time, especially after I have published reports about a <a class=\"color-link\" href=\"https:\/\/www.forbes.com\/sites\/daveywinder\/2025\/12\/14\/lastpass-data-breach---insufficient-security-exposed-16-million-users\/\" data-ga-track=\"InternalLink:https:\/\/www.forbes.com\/sites\/daveywinder\/2025\/12\/14\/lastpass-data-breach---insufficient-security-exposed-16-million-users\/\" target=\"_self\" aria-label=\"password manager data breach\" rel=\"nofollow noopener\">password manager data breach<\/a>, or the latest <a class=\"color-link\" href=\"https:\/\/www.forbes.com\/sites\/daveywinder\/2025\/03\/12\/1password-warning-dont-reset-your-master-password\/\" data-ga-track=\"InternalLink:https:\/\/www.forbes.com\/sites\/daveywinder\/2025\/03\/12\/1password-warning-dont-reset-your-master-password\/\" target=\"_self\" aria-label=\"hack attacks\" rel=\"nofollow noopener\">hack attacks<\/a>. My answer is always the same: yes, absolutely. There is never any doubt in my mind, as an old hacker myself, and for good reason: password reuse and weak passwords make the life of a hacker so much easier. Believe me. The two are most certainly not mutually exclusive, quite the opposite, in fact. People use weak passwords because truly random, truly complex, truly strong ones are almost impossible to remember unless you are some kind of memory savant. Not totally so, of course, I know my 25+ character random master password that unlocks my password manager vault off by heart. I couldn\u2019t actually tell you what it is without a keyboard in front of me, as it\u2019s a muscle memory thing, at least that\u2019s what I call it. I only need to remember the first five characters, and the rest just follow automatically. But even that password would not be considered strong in any way if I were to then refuse it across all my accounts because if one got compromised, then they all get compromised.<\/p>\n<p>It doesn\u2019t matter which password manager you use, provided it is from a trusted vendor. I always recommend standalone managers and apps rather than ones that are part of a web browser, as I prefer some level of separation between the two. But something like Apple Passwords, which comes free with iOS and macOS, is just as good a recommendation as the commercial 1Password application, in my opinion. Don\u2019t let this latest FBI warning go to waste; use it as an opportunity to up your password game.<\/p>\n<p><a class=\"embed-base color-body color-body-border link-embed embed-5\" href=\"https:\/\/www.forbes.com\/sites\/daveywinder\/2025\/12\/13\/google-issues-critical-no-password-required-malware-warning\/\" target=\"_blank\" aria-label=\"Google Confirms Critical No Password Required Attack \u2014 Act Now\" data-ga-track=\"forbesEmbedly:https:\/\/www.forbes.com\/sites\/daveywinder\/2025\/12\/13\/google-issues-critical-no-password-required-malware-warning\/\" rel=\"nofollow noopener\">ForbesGoogle Confirms Critical No Password Required Attack \u2014 Act NowBy Davey Winder<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"FBI reveals 630 million stolen passwords. getty Updated December 14 with password manager usage advice following reports of&hellip;\n","protected":false},"author":2,"featured_media":345618,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[6],"tags":[64,63,191200,191195,191194,191198,191199,90016,191197,191202,191201,191196,105],"class_list":["post-347798","post","type-post","status-publish","format-standard","has-post-thumbnail","category-technology","tag-au","tag-australia","tag-feds","tag-have-i-been-pwned","tag-hibp","tag-my-password-has-been-compromised","tag-my-password-has-been-hacked","tag-password","tag-password-hacked","tag-password-hacking","tag-password-theft","tag-stolen-password","tag-technology"],"_links":{"self":[{"href":"https:\/\/www.newsbeep.com\/au\/wp-json\/wp\/v2\/posts\/347798","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.newsbeep.com\/au\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.newsbeep.com\/au\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/au\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/au\/wp-json\/wp\/v2\/comments?post=347798"}],"version-history":[{"count":0,"href":"https:\/\/www.newsbeep.com\/au\/wp-json\/wp\/v2\/posts\/347798\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/au\/wp-json\/wp\/v2\/media\/345618"}],"wp:attachment":[{"href":"https:\/\/www.newsbeep.com\/au\/wp-json\/wp\/v2\/media?parent=347798"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.newsbeep.com\/au\/wp-json\/wp\/v2\/categories?post=347798"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.newsbeep.com\/au\/wp-json\/wp\/v2\/tags?post=347798"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}