Skip to content

Synthient Credential Stuffing Threat Data

Disclosed Nov 6, 202510 months ago1,957,476,021 accountsUnverified

During 2025, the threat-intelligence firm Synthient aggregated 2 billion unique email addresses disclosed in credential-stuffing lists found across multiple malicious internet sources . Comprised of email addresses and passwords from previous data breaches, these lists are used by attackers to compromise other, unrelated accounts of victims who have reused their passwords. The data also included 1.3 billion unique passwords, which are now searchable in Pwned Passwords. Working to turn breached data into awareness, Synthient partnered with HIBP to help victims of cybercrime understand their exp

What is known

People affected1,957,476,021 (accounts in the leaked data, per Have I Been Pwned)
DisclosedNov 6, 2025
HappenedApr 11, 2025
AttackCredential stuffing
Data exposedEmails, Passwords
SectorTech
StatusUnverified: not yet confirmed by an official notice, a filing or the organization
Check your emailHave I Been Pwned

Sources

Source
Have I Been Pwned: Synthient Credential Stuffing Threat Datahaveibeenpwned.com · Aggregator

Notices filed

WhereFiledPeople
Have I Been Pwnedaccounts in the dataNov 6, 20251,957,476,021
History of this record
  • 2026-09-25 · added · backfill source

First seen 2026-09-25 (Have I Been Pwned). Record counts are as reported. Not legal advice.

Everything about Synthient Credential Stuffing Threat Data

New breaches by email

Wednesdays, only in weeks with newly disclosed breaches, the largest first.

Double opt-in. Unsubscribe any time.