Skip to content

LinkedIn

Disclosed May 21, 201610 years ago164,611,595 accountsConfirmed

Official notice

In May 2016, LinkedIn had 164 million email addresses and passwords exposed . Originally hacked in 2012, the data remained out of sight until being offered for sale on a dark market site 4 years later. The passwords in the breach were stored as SHA1 hashes without salt, the vast majority of which were quickly cracked in the days following the release of the data.

What is known

People affected164,611,595 (accounts in the leaked data, per Have I Been Pwned)
DisclosedMay 21, 2016
HappenedMay 17, 2016
AttackHacking
Data exposedEmails, Passwords, Names, Insurance, Addresses
SectorTech · US
StatusConfirmed
Check your emailHave I Been Pwned

Sources

Source
California Attorney General breach notice: LinkedInoag.ca.gov · Official notice
Have I Been Pwned: LinkedInhaveibeenpwned.com · Aggregator
Maine Attorney General breach notice archive: LinkedInmaine.gov · Official notice

Notices filed

WhereFiledPeople
Have I Been Pwnedaccounts in the dataMay 21, 2016164,611,595
Maine AGresidents of MEMay 27, 2016
California AGresidents of CAJun 2, 2016

Other breaches at LinkedIn

BreachAffected
Scraped LinkedIn profile data offered for saleApr 8, 20215 years agoScraping126Macct
Stolen LinkedIn password hashes posted online; full dump surfaces in 2016Jun 6, 201214 years agoHackingUnknown
History of this record
  • 2026-09-25 · data_types: ["emails","passwords"] to ["emails","passwords","names","insurance","addresses"] · backfill source
  • 2026-09-25 · hibp: empty to LinkedIn · backfill source
  • 2026-09-25 · attack: unknown to hacking · backfill source
  • 2026-09-25 · data_types: [] to ["emails","passwords"] · backfill source
  • 2026-09-25 · records_basis: empty to hibp · backfill source
  • 2026-09-25 · records: empty to 164611595 · backfill source
  • 2026-09-25 · disclosed: 2016-06-02 to 2016-05-21 · backfill source
  • 2026-09-25 · summary: empty to In May 2016, LinkedIn had 164 million email addresses and passwords exposed . Originally hacked in 2012, the data remained out of sight until being offered for sale on a dark market site 4 years later. The passwords in the breach were store · backfill source
  • 2026-09-25 · added · backfill source

First seen 2026-09-25 (California AG), confirmed by California AG. Record counts are as reported. Not legal advice.

Everything about LinkedIn

New breaches by email

Wednesdays, only in weeks with newly disclosed breaches, the largest first.

Double opt-in. Unsubscribe any time.