An infamous dataset of leaked login details, updated last week, now houses 9,948,575,739 passwords and poses the biggest threat to our online security ever

An image showing a rendering gold padlock against a digital background depicting technologies in security systems
(Image credit: MF3d via Getty Images)

Check your passwords, people, because if there was ever a good reason to not reuse the same password, or even variants of the same password, then the latest version of the RockYou collection of leaked or stolen passwords must surely be it. With almost 10 billion unique passwords, the dataset is the largest source of genuine login details, from all around the world, making the risk of cyberattacks as high as it's ever been.

The astonishing number was reported by Cybernews (via Sweclockers) after the updated dataset was posted on a forum used by hackers. Back in 2009, social media company RockYou suffered a data breach in which 32 million user accounts were compromised. Over a decade later, in 2023, a 100 GB text file titled RockYou2021 was posted on hacking forums.

It contained around 8.5 billion passwords, making it then the largest dataset of leaked login details since the 3.2 billion COMB collection in 2022. Now, RockYou2024 is larger still and holds just shy of 10 billion unique email addresses and passwords. Even if one accounts for the fact that every person who's online will have multiple login accounts, the figure is sufficiently large enough to be of major concern.

The biggest danger the compilation poses is that the information can be used to increase the success of credential stuffing, a type of brute force attack that runs through multiple login attempts to gain access to an account. Not only does this put individuals at risk of identity theft, but it also increases the chances of the business hosting the online account from suffering a comprehensive data breach.

This information is then fed back into the RockYou dataset, making it increasingly more potent. Any decent cloud or hosting service will have mechanisms to combat brute force attacks but if a login appears genuine (because it's using a valid email address and password), then there's little the service can do to prevent access.

If this news comes across as being very alarming, then that's a good thing. Because it means people are more likely to take action to prevent the situation from becoming worse.

If you're wondering what exactly you should do, then here's my advice. Never assume that any of your online accounts are safe and never use the same password for any of them—even variations of the same password are risky to use.

I strongly recommend that you change your passwords now, using a combination of three words that you can easily remember, making sure to include numbers and special characters. For any account that offers it, also make sure you enable two-factor or multi-factor authentication (2FA/MFA).

Cybernews offers a password checking service and you can use this to see if a specific password appears in the RockYou2024 dataset. It's safe to do this because you're not providing any other details, such as an email address, that would identify the password with a particular account. Even if one of your passwords isn't in the database, I still recommend that you add a layer of security to your online accounts. If it doesn't offer one, then it's even more important you change the password to a large and complex one right now.

Best gaming PCBest gaming laptop


Best gaming PC: The top pre-built machines.
Best gaming laptop: Great devices for mobile gaming.

Nick Evanson
Hardware Writer

Nick, gaming, and computers all first met in 1981, with the love affair starting on a Sinclair ZX81 in kit form and a book on ZX Basic. He ended up becoming a physics and IT teacher, but by the late 1990s decided it was time to cut his teeth writing for a long defunct UK tech site. He went on to do the same at Madonion, helping to write the help files for 3DMark and PCMark. After a short stint working at Beyond3D.com, Nick joined Futuremark (MadOnion rebranded) full-time, as editor-in-chief for its gaming and hardware section, YouGamers. After the site shutdown, he became an engineering and computing lecturer for many years, but missed the writing bug. Cue four years at TechSpot.com and over 100 long articles on anything and everything. He freely admits to being far too obsessed with GPUs and open world grindy RPGs, but who isn't these days? 

Read more
Kinzie, in an FBI jacket, uses a computer with the logo of the Third Street Saints on it
Have I Been Pwned adds over 284 million compromised passwords from latest breach
Hacker
$1.5 billion crypto heist could be the biggest yet, more than doubling the previous record, but don't worry: The affected firm says it can take the hit
3D illustration of a grid of black cpus with different IoT symbols, representing a botnet concept
Cloudflare claims to have mitigated biggest DDoS attack on record with requests flying in from 5,500 IP addresses per second
An image of a fake Bitcoin with a laptop in the background displaying financial data
North Korean hackers are said to have stolen $1,300,000,000 in crypto in 2024, an estimated 61% of the total funds swiped this year
Mister Fantastic giving a thumbs up
A Marvel Rivals player has uncovered 'one of the most dangerous vulnerabilities a game can have' that'll let cheaters take over your PC and find your passwords
Image manipulated symbolic alegory pointing into the mystery of being.
Deep trouble: Infosec firm finds a DeepSeek database 'completely open and unauthenticated' exposing chat history, API keys, and operational details
Latest in Security
An FBI wanted poster for alleged hacker Zhou Shuai.
US Justice Dept announces $10 million bounty on at-large 'hacker-for-hire' cabal it says targeted China critics, religious missionaries, and the Treasury
Kinzie, in an FBI jacket, uses a computer with the logo of the Third Street Saints on it
Have I Been Pwned adds over 284 million compromised passwords from latest breach
A still from a YouTube video of Senator Mark Warner speaking
Telecoms hack on US government officials is 'worst in nations history' and 'the barn door is still wide open' says senator
HDMI cable
Hackers can wirelessly spy on your display by collecting HDMI signal leaks and churning them through an AI, but I wouldn't break out the tin foil just yet
Computer code and text displayed on computer screens. Photographer: Chris Ratcliffe/Bloomberg
Forcing users to periodically change their passwords should go the way of the dodo according to the US government
An original Apple Macintosh Model M0001, as they celebrate 40th anniversary, is on display in between 2024 Apple models at the independent Apple products store chain Amac, on January 24, 2024 in Utrecht, The Netherlands. Based on the Motorola 68000 microprocessor, the Macintosh was the first successful mouse-driven computer with a graphical user interface.
Major browser providers scramble to patch an 18-year-old vulnerability affecting MacOS and Linux systems but Windows remains gloriously immune
Latest in News
Pedro Pascal as Joel in a coat in winter looking unhappy
'Don't you know what he did?': The truth comes out in The Last of Us Season 2 trailer
Aloy
'Creepy,' 'ghastly,' 'rancid': Viewers react to leaked video of Sony's AI-powered Aloy
Split Fiction trailer still - Zoe and Mio standing side by side, wearing glowing neon sci-fi jammies
Split Fiction sells 1 million copies over 2 days
A soldier looks out over the Verdansk map, as a single tear rolls down his cheek.
The original Verdansk map is returning to Call of Duty: Warzone, to celebrate which we get a soldier crying to Nat King Cole
More than 5 years after launch, Control gets a surprise patch that lets everyone play the Hideo Kojima mission
Swen Vincke
Swen Vincke stamps seal of approval on Stardew Valley mod that yoinks the Baldur's Gate 3 cast out of D&D and into a cosy pastoral life