{"id":90109,"date":"2021-06-29T11:25:07","date_gmt":"2021-06-29T05:55:07","guid":{"rendered":"https:\/\/blogs.quickheal.com\/?p=90109"},"modified":"2024-03-20T16:31:29","modified_gmt":"2024-03-20T11:01:29","slug":"rockyou2021-massive-data-leak-of-passwords-on-the-dark-web","status":"publish","type":"post","link":"https:\/\/www.quickheal.com\/blogs\/rockyou2021-massive-data-leak-of-passwords-on-the-dark-web\/","title":{"rendered":"RockYou2021: Massive data leak of passwords on the dark web"},"content":{"rendered":"<p>&nbsp;<\/p>\n<p>The issue of\u00a0<a href=\"https:\/\/blogs.quickheal.com\/data-breach-severity-understanding\/\" target=\"_blank\" rel=\"noopener noreferrer\"><span data-preserver-spaces=\"true\">a data breach<\/span><\/a><span data-preserver-spaces=\"true\">\u00a0continues to plague the world of cybersecurity. What seems to be the most extensive password collection of all time has been leaked on the dark web. The source? An anonymous forum poster uploaded a 100GB TXT compilation file of stolen and leaked passwords, containing 8.4 billion entries.\u00a0<\/span><\/p>\n<p>Here\u2019s everything you need to know about the massive data leak \u201cRockYou2021\u201d and how to secure your data and avoid potential harm from threat actors.<\/p>\n<h3><\/h3>\n<h2 style=\"font-size: 27px;\"><strong>What is RockYou2021?<\/strong><\/h2>\n<p>RockYou2021 is dubbed as the mother of all <a href=\"https:\/\/blogs.quickheal.com\/breaches-and-incidents-top-5-cyber-attacks-in-quarter-1-2021\/\" target=\"_blank\" rel=\"noopener noreferrer\">password<\/a> leaks! According to the <a href=\"https:\/\/www.lifewire.com\/rockyou2021-breached-data-puts-billions-of-accounts-at-risk-5188262\" target=\"_blank\" rel=\"noopener noreferrer\">reports<\/a>, the forum user named the collection RockYou2021 in reference to the 2009 <a href=\"https:\/\/techcrunch.com\/2009\/12\/14\/rockyou-hack-security-myspace-facebook-passwords\/\" target=\"_blank\" rel=\"noopener noreferrer\">RockYou<\/a> data breach, where 32 million leaked passwords had been stored in plaintext.<\/p>\n<p>Considering that the total number of Internet users is\u00a0<a href=\"https:\/\/wearesocial.com\/blog\/2021\/04\/60-percent-of-the-worlds-population-is-now-online\" target=\"_blank\" rel=\"noopener noreferrer\">estimated<\/a>\u00a0to be approximately 4.7 billion, the number of leaked credential data is staggering! The perpetrators likely possess multiple passwords used by millions of people.<\/p>\n<p>As per security analysts who have examined the data breach, none of the leaked passwords is new but seems to have been compiled over several years. Many of the passwords in the file have been leaked in previous data breaches, including the <a href=\"https:\/\/cybernews.com\/news\/largest-compilation-of-emails-and-passwords-leaked-free\/\" target=\"_blank\" rel=\"noopener noreferrer\">Combination of Many Breaches<\/a>\u00a0in February 2021, which leaked 3.2 billion records online.<\/p>\n<p>The person who uploaded this text file has claimed that all the passwords in the list are 6-20 characters long, and non-ASCII characters &amp; white spaces have been removed. The person had also claimed that 82 million passwords had been leaked, but an investigation by security analysts has proved that it is actually ten times less. However, it remains the largest password and credentials leak of its kind in history.<\/p>\n<h3><\/h3>\n<h2 style=\"font-size: 27px;\"><strong>Does it affect me?<\/strong><\/h2>\n<p>The sheer scale of the number of leaked passwords, even the actual figure of 8.4 billion, is massive. A password you use could well be on the leaked list. Threat actors could use the credentials provided on the list to carry out\u00a0<a href=\"https:\/\/blogs.quickheal.com\/malicious-bots-targeting-e-commerce-travel-customers-threat\/\" target=\"_blank\" rel=\"noopener noreferrer\">credential stuffing attacks<\/a>. So yes, if you are an Internet user with an online account, the RockYou2021 data breach could very well affect you.<\/p>\n<p>With RockYou2021, hackers are looking to begin mass credential stuffing or more targeted credentials attacks. Given that your data was likely to be involved in this leak, you need to reset your passwords.<\/p>\n<p>&nbsp;<\/p>\n<h2 style=\"font-size: 27px;\"><strong>Tips to keep in mind to ensure the security of your account<\/strong><\/h2>\n<ul>\n<li><strong>Check if your data has been leaked \u2013\u00a0<\/strong>Since the entire RockYou2021 password list contains data collected over many years, it is a good idea to check if any of your data, even if it is old, appears in the list. Many websites allow you to check if your password has been breached \u2013 you can click on this\u00a0<a href=\"https:\/\/blogs.quickheal.com\/check-if-your-online-account-has-been-leaked-in-a-data-breach\/\" target=\"_blank\" rel=\"noopener noreferrer\">Quick Heal article<\/a>\u00a0for step-by-step instructions. However, ensure that you only use trusted and verified sites for this purpose \u2013 you don&#8217;t want to leak your password unintentionally! Change your password immediately and everywhere if your current password appears to have been breached.<\/li>\n<li><strong>Change your passwords \u2013\u00a0<\/strong>Regardless of whether your password appears on this list, it is a good idea to\u00a0<a href=\"https:\/\/blogs.quickheal.com\/5-common-password-mistakes-tips-creating-stronger-passwords\/\" target=\"_blank\" rel=\"noopener noreferrer\">change your online passwords.<\/a>\u00a0You never know when your password (or other credential data) could be leaked, so that is why it is a good habit to change your passwords regularly.<\/li>\n<li><strong>Use hard and complex passwords \u2013<\/strong>\u00a0Changing passwords is a good habit, but it is not of much use if you use easily guessable passwords such as words from the dictionary, your name, or simply &#8220;password.&#8221; Use\u00a0<a href=\"https:\/\/blogs.quickheal.com\/security-habit-to-make-strong-passwords-for-stronger-security\/\" target=\"_blank\" rel=\"noopener noreferrer\">complex and challenging passwords<\/a>, which are a combination of alphabets, numbers, and special characters.<\/li>\n<li><strong>Use different passwords for different accounts \u2013<\/strong>\u00a0Using one password everywhere on the Internet is unsafe. You can create a very complex password, but you can still be the victim of a data breach. And if you use that breached password for all your online accounts, you could easily be exploited by a threat actor. So, use different complex passwords for other accounts, which will help you stay much safer on the Internet.<\/li>\n<li><strong>Start using multi-factor authentication \u2013\u00a0<\/strong>The online world is moving away from its dependence on passwords, and you should too. If you have the option, enable\u00a0<a href=\"https:\/\/blogs.quickheal.com\/staying-safe-on-social-media-five-things-to-keep-in-mind\/\" target=\"_blank\" rel=\"noopener noreferrer\">multi-factor authentication<\/a>\u00a0in your online accounts to add an extra layer of security.<\/li>\n<li><strong>Watch out for phishing attempts \u2013<\/strong>\u00a0As always, stay on your guard against unsolicited and suspicious calls, messages and emails. Don&#8217;t click on links unless you are sure where they will lead you to. Be very careful about how and where you use your data.<\/li>\n<li><strong>Use robust Internet Security solutions \u2013\u00a0<\/strong>Stay safe on the Internet using\u00a0<a href=\"https:\/\/www.quickheal.co.in\/quick-heal-internet-security\" target=\"_blank\" rel=\"noopener noreferrer\">Quick Heal Internet Security<\/a>\u00a0which offers the\u00a0<a href=\"https:\/\/www.quickheal.co.in\/documents\/datasheet\/is-datasheet.pdf\" target=\"_blank\" rel=\"noopener noreferrer\">ultimate security<\/a>\u00a0for all your Internet needs. Access the Internet in peace as Quick Heal Internet&#8217;s Security large array of powerful features, including Safe Banking and Wi-Fi Scanner, proactively keep you safe online.<\/li>\n<\/ul>\n<p>&nbsp;<\/p>\n<p>Now&#8217;s the perfect time to update your passwords and turn on MFA. We strongly encourage everyone to take the necessary measures to protect yourself from identity theft. Data breaches are all too common and we all have to stay vigilant.<\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>&nbsp; The issue of\u00a0a data breach\u00a0continues to plague the world of cybersecurity. What seems to be the most extensive password collection of all time has been leaked on the dark web. The source? An anonymous forum poster uploaded a 100GB TXT compilation file of stolen and leaked passwords, containing 8.4 billion entries.\u00a0 Here\u2019s everything you [&hellip;]<\/p>\n","protected":false},"author":75,"featured_media":90110,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1529,151],"tags":[1840,1842,1841,534,58,769],"class_list":["post-90109","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-data-breach","category-password","tag-databreach","tag-newsalert","tag-rockyou2021","tag-cybersecurity","tag-hacking","tag-passwords"],"aioseo_notices":[],"_links":{"self":[{"href":"https:\/\/www.quickheal.com\/blogs\/wp-json\/wp\/v2\/posts\/90109"}],"collection":[{"href":"https:\/\/www.quickheal.com\/blogs\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.quickheal.com\/blogs\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.quickheal.com\/blogs\/wp-json\/wp\/v2\/users\/75"}],"replies":[{"embeddable":true,"href":"https:\/\/www.quickheal.com\/blogs\/wp-json\/wp\/v2\/comments?post=90109"}],"version-history":[{"count":4,"href":"https:\/\/www.quickheal.com\/blogs\/wp-json\/wp\/v2\/posts\/90109\/revisions"}],"predecessor-version":[{"id":91461,"href":"https:\/\/www.quickheal.com\/blogs\/wp-json\/wp\/v2\/posts\/90109\/revisions\/91461"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.quickheal.com\/blogs\/wp-json\/wp\/v2\/media\/90110"}],"wp:attachment":[{"href":"https:\/\/www.quickheal.com\/blogs\/wp-json\/wp\/v2\/media?parent=90109"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.quickheal.com\/blogs\/wp-json\/wp\/v2\/categories?post=90109"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.quickheal.com\/blogs\/wp-json\/wp\/v2\/tags?post=90109"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}