Cyber Security News

Have I Been Pwned Added 284 Million Accounts Stolen by Information Stealer Malware

Have I Been Pwned (HIBP) has incorporated 284 million email addresses compromised by information-stealer malware into its breach notification service.

The data originates from a 1.5TB corpus of stealer logs dubbed “ALIEN TXTBASE”, marking one of the largest malware-related dataset incorporations in HIBP’s 11-year history. 

This update expands HIBP’s repository to include 493 million unique website-email pairs and introduces critical tools for organizations to combat credential-based attacks.

Origin of ALIEN TXTBASE

The dataset emerged from a Telegram channel operated by cybercriminals distributing stealer logs—records of credentials harvested by malware like RedLine or Vidar. 

These logs capture keystrokes, browser-stored passwords, and authentication cookies from infected devices. 

HIBP founder Troy Hunt collaborated with international government agencies to acquire the 744-file corpus, which contained 23 billion raw entries of credentials extracted from victims’ machines.

Verification involved cross-referencing entries against target services. For example, Netflix accounts listed in the logs were confirmed via geofenced password reset flows—accessing country-specific login portals (e.g., /ph-en/login for Philippine users) through VPNs. 

Hunt validated geographic consistency by testing entries against localized authentication endpoints, confirming both account existence and the malware’s accuracy in capturing login contexts.

Enterprise-Focused Search APIs

HIBP introduced two GraphQL APIs under its Pwned 5 subscription tier to help organizations mitigate risks:

Domain-Centric Stealer Log Search: Allows domain administrators to retrieve all email aliases (e.g., john@ in john@example.com) and associated website domains (e.g., netflix.com) from their DNS-controlled domains. Outputs JSON mappings like {“john”: [“netflix.com”]}.

Website Operator Search: Enables service providers like Netflix to fetch all email addresses exposed in stealer logs when users enter credentials into their domains, returning arrays like [“john@example.com”].

These APIs address credential-stuffing attack vectors by letting enterprises identify compromised accounts and enforce multi-factor authentication or password resets. 

The Pwned 5 tier provides 1,000 requests/minute rate limits, with pricing starting at $3,500/month for sustained access.

HIBP’s open-source password breach repository added 244 million new unique passwords from ALIEN TXTBASE, including patterns like tender-kangaroo and CaptainKangaroo. 

The service now contains over 13 billion compromised credentials, with 10 billion API monthly requests informing password policies globally. The k-anonymity model ensures users can check passwords securely via partial SHA-1 hash prefixes.

Implications for Cybersecurity

This update shifts how enterprises approach attack surface management:

  • SOC Teams can now trace credential leaks to specific malware campaigns rather than generic “third-party breaches.”
  • Identity Providers like Okta or Microsoft Entra ID gain actionable data to harden conditional access policies against stealer-log-sourced credentials.
  • CISO Prioritization: With HIBP’s IsStealerLog breach flag, organizations can triage incidents involving direct malware compromises over bulk database dumps.

Hunt emphasized that while the Telegram-distributed logs represent a fraction of global stealer activity, integrating them into HIBP disrupts attackers’ economic models by converting exclusive data into public awareness. 

The service now processes 10,000 new compromised accounts/minute from ongoing malware operations, underscoring the relentless growth of credential-based threats.

The ALIEN TXTBASE integration exemplifies HIBP’s evolution from a breach-notification tool to a critical infrastructure component in modern cybersecurity.

By transforming raw stealer logs into actionable intelligence, HIBP equips enterprises and individuals to preempt account takeovers—proving that even data born from criminal endeavors can be weaponized for defense. 

As Hunt noted, this corpus is “just one of many channels,” but its inclusion marks a pivotal step in democratizing access to malware intelligence.

Collect Threat Intelligence on the Latest Malware and Phishing Attacks with ANY.RUN TI Lookup -> Try for free

Kaaviya

Kaaviya is a Security Editor and fellow reporter with Cyber Security News. She is covering various cyber security incidents happening in the Cyber Space.

Recent Posts

Google Chrome 153 Update Fixes 42 Security Flaws, Including 3 Critical Ones

Google has released an important Chrome 153 security update that fixes 42 vulnerabilities across the…

2 hours ago

CISA and NIST Release Technical Checklist for Safeguarding Identity Tokens From Theft and Misuse

The Cybersecurity and Infrastructure Security Agency (CISA) and the National Institute of Standards and Technology…

12 hours ago

CISA Shares 17 Techniques Used by Hackers to Compromise Active Directory Environments

CISA and five international cybersecurity agencies have released detailed guidance describing 17 common techniques hackers…

13 hours ago

Apple Rolls Out Massive Security Update Fixing 273 Vulnerabilities Across Its Devices

Apple has released one of its largest coordinated security rollouts, addressing 273 distinct critical vulnerabilities…

13 hours ago

How to Keep Malware’s Rotating Infrastructure From Becoming a Detection Gap

You can’t detect today's attacks with yesterday’s threat intelligence; that’s how you could briefly formulate…

13 hours ago

Microsoft Bans Its AI Models From Launching Cyberattacks or Escalating Their Own Access

Microsoft has published a draft Humanist AI Code of Conduct that would prohibit its in-house…

13 hours ago