TIME Security

This Hacker Reportedly Stole Millions of Email Passwords

You should probably update your password just to be safe

Those using email powered by Google, Yahoo, or Microsoft might want to consider updating their passwords. A hacker in Russia obtained “tens of millions” of login credentials for email services provided by those companies, Reuters reports.

Hold Security discovered the hack and recovered the data, which included login information for 272.3 million accounts. Many of the compromised email login credentials belonged to users of popular Russian provider Mail.ru. The data included logins for email services provided by Google, Yahoo, and Microsoft.

[video id=kCXAmgKD]

“Unfortunately, there are places on the internet where leaked and stolen credentials are posted, and when we come across these or someone sends them to us, we act to protect customers,” a Microsoft spokesperson said in a comment to TIME. “Microsoft has security measures in place to detect account compromise and requires additional information to verify the account owner and help them regain sole access to their account.”

The hacker is offering to sell the login information for less than $1, Reuters reports. Hold Security’s policy doesn’t allow it to pay for stolen data, even if it is a trivial sum of money. Instead, the researchers added likes to the hacker’s social media page and posted positive comments about him in hacker forums in exchange for the data.

Although the breach sounds alarming, it may not be as concerning as it seems. After a first check, Mail.ru concluded that none of the stolen email and password combinations actually work, a Mail.ru spokesperson told Motherboard.

Yahoo’s security team investigated the situation, and the company doesn’t “believe there is any significant risk to our users based on the claims shared with the press,” a Yahoo spokesperson said in a statement to TIME.

Read more: 5 Tips for Staying Safe Online From a Google Security Expert

Google faced a similar situation roughly two years ago, when it said that less than 2% of the username and password combinations recovered from a string of data dumps in September 2014 might have worked.

When asked for comment about the latest hack, Google told TIME it wouldn’t comment on specific incidents.

Tap to read full story

Your browser is out of date. Please update your browser at http://update.microsoft.com


YOU BROKE TIME.COM!

Dear TIME Reader,

As a regular visitor to TIME.com, we are sure you enjoy all the great journalism created by our editors and reporters. Great journalism has great value, and it costs money to make it. One of the main ways we cover our costs is through advertising.

The use of software that blocks ads limits our ability to provide you with the journalism you enjoy. Consider turning your Ad Blocker off so that we can continue to provide the world class journalism you have become accustomed to.

The TIME Team