← LinkedIn

2012 password breach (hashes leaked 2016)

2012 164.0M records affected Share on X

Data compromised

Email addresses, Passwords (hashed)

Technical writeup

In 2012 LinkedIn suffered a breach where password hashes were stolen. The hashes were SHA-1 without per-user salts. In 2016 a trove of 164 million email and hashed password pairs was put up for sale; many hashes were cracked due to weak hashing.

Root cause

Use of unsalted SHA-1 for password hashing; breach went undetected until hashes appeared for sale years later.

References