In May 2016, LinkedIn had 164 million email addresses and passwords exposed . Originally hacked in 2012, the data remained out of sight until being offered for sale on a dark market site 4 years later. The passwords in the breach were stored as SHA1 hashes without salt, the vast majority of which were quickly cracked in the days following the release of the data.
What is known
People affected
164,611,595 (accounts in the leaked data, per Have I Been Pwned)
2026-09-25 · data_types: ["emails","passwords"] to ["emails","passwords","names","insurance","addresses"] · backfill source
2026-09-25 · hibp: empty to LinkedIn · backfill source
2026-09-25 · attack: unknown to hacking · backfill source
2026-09-25 · data_types: [] to ["emails","passwords"] · backfill source
2026-09-25 · records_basis: empty to hibp · backfill source
2026-09-25 · records: empty to 164611595 · backfill source
2026-09-25 · disclosed: 2016-06-02 to 2016-05-21 · backfill source
2026-09-25 · summary: empty to In May 2016, LinkedIn had 164 million email addresses and passwords exposed . Originally hacked in 2012, the data remained out of sight until being offered for sale on a dark market site 4 years later. The passwords in the breach were store · backfill source