RockYou
Disclosed Dec 14, 200916 years ago32,000,000 affectedSettled
SQL injection exposes 32 million plaintext passwords at RockYou
A hacker used a SQL injection flaw to access RockYou's database of more than 32 million accounts, which stored passwords in plain text; the password list became a standard cracking wordlist.
What is known
| People affected | 32,000,000 (as reported by the organization) |
|---|---|
| Disclosed | Dec 14, 2009 |
| Attack | Hacking |
| Data exposed | Emails, Passwords, Credentials and tokens |
| Sector | Tech · US |
| Status | Settled |
| Lawsuit or fine | FTC settlement including $250,000 COPPA civil penalty (2012) (about $250K) |
Sources
| Source | |
|---|---|
| RockYou Hack: From Bad To Worsetechcrunch.com · News | News |
| FTC: RockYou, Inc. (FTC Charges That Security Flaws in RockYou Game Site Exposed 32 Million Email Addresses and Passwords)ftc.gov · Regulator | Regulator |
Notices filed
| Where | Filed | People |
|---|---|---|
| Researchtotal | Dec 14, 2009 | 32,000,000 |
History of this record
- 2026-09-25 · added · seed source
First seen 2026-09-25 (Research), confirmed by Research. Record counts are as reported. Not legal advice.