2012 password breach (hashes leaked 2016)
Data compromised
Email addresses, Passwords (hashed)
Technical writeup
In 2012 LinkedIn suffered a breach where password hashes were stolen. The hashes were SHA-1 without per-user salts. In 2016 a trove of 164 million email and hashed password pairs was put up for sale; many hashes were cracked due to weak hashing.
Root cause
Use of unsalted SHA-1 for password hashing; breach went undetected until hashes appeared for sale years later.