‘RockYou2024’: Nearly 10 billion passwords leaked online


On a popular hacking form, a user has leaked a file that contains 9,948,575,739 unique plaintext passwords. The list appears to be a compilation of passwords that were obtained during several old and more recent data breaches.

The list is referred to as RockYou2024 because of its filename, rockyou.txt. To cybercriminals the list has some value because it contains real-world passwords. This means if an attacker tried this list of passwords to try to break into an account (known as a brute force attack) they’s be more likely to get in than just trying a list of any old letters and words.

Read more…
Source: Malwarebytes Labs


Sign up for our Newsletter


Related:

  • Asos customers receive ‘hack’ notification threatening to leak data

    October 6, 2026

    Asos is investigating after users of its mobile app received a notification claiming hackers had “fully compromised” the online fashion retailer’s data. The value of Asos’s shares on the London Stock Exchange dived more than 14% after thousands of customers received a notification titled “Asos hacked” with a link that sent them to the Telegram messaging ...

  • Blinder Tunnel Campaign Targets Iraqi Infrastructure

    October 6, 2026

    Palo Alto Unit 42 discovered that an Iranian state-aligned threat actor has been masquerading as the Dubai Airports IT department to deliver trojanized coding challenges to high-value targets. Unit 42 tracks the activity as CL-STA-1178. This activity includes a campaign they call “Blinder Tunnel,” that targeted Iraqi critical infrastructure in March 2026, following infrastructure staging ...

  • Hackers access data of 8.8 million people in Denmark in ‘extremely serious’ breach

    October 5, 2026

    A major cybersecurity breach has exposed the personal data of 8.8 million people in Denmark. Denmark has suffered a major data breach after hackers broke into the country’s national population registry and accessed the personal information of millions of people. The country’s digital affairs minister announced the data breach on Monday, calling it “an extremely serious incident” ...

  • ShinyHunters hacker in FBI data theft detained in Jordan, cooperating with bureau

    October 3, 2026

    A suspected member of the ShinyHunters hacking group, which ​says it stole data on every FBI employee, was detained in Jordan this week and is cooperating with the FBI, three people familiar with the matter told Reuters. Saif ‌al-Din Khader was detained by Jordanian authorities, the three sources said. Two of them said he was brought ...

  • AI agents aggressively tried to hack US and Canadian government websites

    October 2, 2026

    AI agents simply won’t take ‘no’ for an answer. Security researchers from nonprofit Transluce found bots making numerous attempts to hack US and Canadian government websites in search of private information. In a new report, Transluce singled out two incidents: one against the US Department of Education, and one against Library and Archives Canada. Both seem ...

  • SMTP is the key: BPFDoor and AVERAT hitting the network edge

    October 2, 2026

    Rapid7 tracked a set of Linux samples that blend into the software and device conventions of the telecom environments they target. The set spans a newly observed BPFDoor variant, a BPF Rekoobe build seen against South Korean targets, a dropper, and six builds of a Linux implant Rapid7 researchers track as AVERAT, deployed against Taiwanese ...