Skip to content

RockYou

Disclosed Dec 14, 200916 years ago32,000,000 affectedSettled

Official notice

SQL injection exposes 32 million plaintext passwords at RockYou

A hacker used a SQL injection flaw to access RockYou's database of more than 32 million accounts, which stored passwords in plain text; the password list became a standard cracking wordlist.

What is known

People affected32,000,000 (as reported by the organization)
DisclosedDec 14, 2009
AttackHacking
Data exposedEmails, Passwords, Credentials and tokens
SectorTech · US
StatusSettled
Lawsuit or fineFTC settlement including $250,000 COPPA civil penalty (2012) (about $250K)

Sources

Notices filed

WhereFiledPeople
ResearchtotalDec 14, 200932,000,000
History of this record
  • 2026-09-25 · added · seed source

First seen 2026-09-25 (Research), confirmed by Research. Record counts are as reported. Not legal advice.

Everything about RockYou

New breaches by email

Wednesdays, only in weeks with newly disclosed breaches, the largest first.

Double opt-in. Unsubscribe any time.