711 million email addresses and passwords dumped.

Ive only got 2x emails, so will just change the passwords anyway.

It's not that simple. The leaked passwords are (probably) not email account passwords. The leaks are from unknown websites you've signed up to using that email address.
Even if you use a different password for every site you sign up to, you still dont know which password has been leaked so to be 100% secure you'd have to change every password.

It says in the blog post that the emails + passwords were used in an attempt to send email but the actual data is probably "aggregations from various other breach sources". So username+password combos from other breaches being used to try and "log in" to your email account - most likely not the correct email account password unless you reuse the same passwords. If you have an email address and password on the list, you still dont know which password has been leaked.

edit: it's still a good idea to change your email passwords anyway
 
Last edited:
it does say at the bottom under the site which was compromised if its email password or both.

It says Email Addresses, Passwords.

Or does that translate to 'both'?

Does that then also mean email address/password for that email address? Or just that email address on a specific website?
 
not to mention, if anyone tries to log in to my account I need to confirm it first, and I get an email sent to me stating someones trying to log in...?
 
so you are all inputing your email addresses into a site called haveibeenpwnd"? ok :p that's clever .. :D




blahh i had my virgin account compromised last month.. I didn't even think to check it had two stage authentication..
 
It's times like this I seriously consider apps like dashlane or Keepass. But then at the same time of you're in the habit of remembering very secure passwords with 2FA as well anyway, it renders those apps unecessary.

But it's made me think of those 2FA usb keys you plug in. Need to relook into those :)
 
Back
Top Bottom