Have I Been Pwned (HIBP) has incorporated a new dataset containing 183 million unique stolen email and password pairs, sourced and aggregated by a U.S. college student known as Ben for the cybersecurity company Synthient. The dataset, totaling 23 billion rows and 3.5 terabytes, was compiled from infostealer malware logs, Telegram groups, Tor sites, and various underground forums, reflecting the industrial scale at which credentials are stolen, traded, and reused across the dark web. Security experts note that this aggregation highlights the persistent threat posed by credential theft, password reuse, and the automation of attacks, which collectively undermine digital trust and make traditional defenses less effective.
The Synthient dataset is notable for its breadth, as it combines real credentials captured from infostealer malware with credential stuffing lists, rather than being the result of a single breach. This collection process demonstrates how stolen credentials move through a digital supply chain, being shared, merged, and resold repeatedly. The exposure of such a vast number of credentials underscores the importance of maintaining visibility into leaked data, enforcing multi-factor authentication, and adopting stronger authentication practices to mitigate the risks associated with widespread credential compromise.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
Google said reports framing the exposed records as a new large-scale Gmail data breach were false, clarifying that the credentials were aggregated from infostealer activity and other sources rather than a direct compromise of Google. The response helped reframe the incident as credential aggregation, not a single-platform breach.
Troy Hunt added 183 million unique email address and password pairs from the Synthient dataset to Have I Been Pwned. The update made the stolen credentials searchable for affected users and highlighted the scale of industrialized credential theft.
A U.S. college student known as Ben, working for Synthient, assembled a dataset containing roughly 23 billion rows from infostealer malware logs, Telegram groups, and online forums. The collection represented aggregated stolen credentials from many sources rather than a single breach.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
6 references tracked. Mallory keeps watching after this page renders.
zdnet.com
Open sourcebleepingcomputer.com
Open sourcetroyhunt.com
Open sourcehackread.com
Open sourcescworld.com
Open sourcetroyhunt.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.