Over 10 Billion Passwords Have Been Exposed in the Largest Password Hack in History The data is thought to have been collected over the past two decades.

By Emily Rella Edited by Melissa Malamut

Key Takeaways

  • A text file called RockYou2024 was uploaded to the dark web on July 4, exposing over 10 billion unique passwords.
  • It marks the largest password leak in history.

Opinions expressed by Entrepreneur contributors are their own.

A massive hack occurred over the July 4th holiday when 10 billion unique passwords were exposed from users and customers across a slew of popular websites, including Ticketmaster and Santander.

The plain text file, called RockYou2024, leaked the passwords of customers all over the world. The data is thought to have been collected through a series of hacks over two decades.

Related: Ticketmaster Hack Affects Over 560 Million Customers

"In its essence, the RockYou2024 leak is a compilation of real-world passwords used by individuals all over the world. Revealing that many passwords for threat actors substantially heightens the risk of credential stuffing attacks," researchers for CyberNews said. "Threat actors could exploit the RockYou2024 password compilation to conduct brute-force attacks and gain unauthorized access to various online accounts used by individuals who employ passwords included in the dataset."

The CyberNews team noted the leak, combined with other breaches that exposed email addresses and phone numbers, could lead to "a cascade of data breaches, financial frauds, and identity thefts."

Bad actors could attempt attacks on anything from "internet-facing cameras and even industrial hardware," they added.

For example, if a hacker sees that your email address is associated with the password in the RockYou2024 file, it might check to see if you use the same password for your email address for another company leaked in a separate hack.

Though this hack is said to be the largest in history, it's not the first "RockYou" event.

Related: AT&T Customer Data Leaked to 'Dark Web,' Millions Affected

In 2021, RockYou2021 was published, containing an estimated 8.4 billion passwords. RockYou2024 is thought to include these passwords plus an additional 1.5 billion collected over the past three years. RockYou2021 was primarily composed of social media account passwords.

CyberNews recommends changing passwords used across multiple websites or accounts and enabling multi-factor authorization on any devices possible.

Emily Rella

Senior News Writer

Emily Rella is a Senior News Writer at Entrepreneur.com. Previously, she was an editor at Verizon Media. Her coverage spans features, business, lifestyle, tech, entertainment, and lifestyle. She is a 2015 graduate of Boston College and a Ridgefield, CT native. Find her on Twitter at @EmilyKRella.

Want to be an Entrepreneur Leadership Network contributor? Apply now to join.

Editor's Pick

Business News

JPMorgan Shuts Down Internal Message Board Comments After Employees React to Return-to-Office Mandate

Employees were given the option to leave comments about the RTO mandate with their first and last names on display — and they did not hold back.

Innovation

4 Ways Market Leaders Use Innovation to Foster Business Growth

Forward-thinkers constantly strive to diversify and streamline their products and services, turning novelties into commodities desired by many.

Franchise

Jersey Mike's Switched Up Its Strategy for Serving Customers This Year — Then Blackstone Bought the Sandwich Chain for $8 Billion

The New Jersey sub franchise has dialed in on strategies to serve customers in stores and online, as proven by its recent acquisition.

Science & Technology

Is Mental Clarity the Real Key to Success in 2025?

Peak mental efficiency = peak business effectiveness.

Business Ideas

70 Small Business Ideas to Start in 2025

We put together a list of the best, most profitable small business ideas for entrepreneurs to pursue in 2025.