uniladtech homepage
  • News
    • Tech News
    • AI
  • Gadgets
    • Apple
    • iPhone
  • Gaming
    • Playstation
    • Xbox
  • Science
    • News
    • Space
  • Streaming
    • Netflix
  • Vehicles
    • Car News
  • Social Media
    • WhatsApp
    • YouTube
  • Advertise
  • Terms
  • Privacy & Cookies
  • LADbible Group
  • LADbible
  • UNILAD
  • SPORTbible
  • GAMINGbible
  • Tyla
  • FOODbible
  • License Our Content
  • About Us & Contact
  • Jobs
  • Latest
  • Archive
  • Topics A-Z
  • Authors
Facebook
Instagram
X
TikTok
Snapchat
WhatsApp
Submit Your Content
Experts urge people to act fast as 19,000,000,000 passwords are leaked in major hack
Home>News>Tech News
Published 12:48 7 May 2025 GMT+1

Experts urge people to act fast as 19,000,000,000 passwords are leaked in major hack

Another day, another cyber attack

Tom Chapman

Tom Chapman

google discoverFollow us on Google Discover
Featured Image Credit: Rawf8 / Getty
Cybersecurity
Tech News

Advert

Advert

Advert

We're all warned about the continued dangers of cyber attacks in 2025, but according to a new report, things could be even more desperate than we first thought.

Cybersecurity crackdowns are everywhere, but unfortunately, that doesn't stop bad actors from slipping through the virtual net and getting into our private details.

Microsoft has already tried to ditch password sign-ins as an attempt to bamboozle hackers, and as we've seen, it can take mere milliseconds to crack the average password.

Forbes' Davey Winder has been keeping an eye on the password pandemic, previously estimating that passwords finding their way onto the dark web has risen from 800 million to up to 2.1 billion.

Advert

The password pandemic is only getting worse (Richard Newstead / Getty)
The password pandemic is only getting worse (Richard Newstead / Getty)

In a new report, Winder claims that infostealer malware attacks could be responsible for even more leaks, potentially meaning a jaw-dropping 19 billion passwords are out there and up for grabs.

Since April 2024, there have apparently been 200 security incidents, leading to 19,030,305,929 hacked passwords being readily available online.

Winder warns: "The takeaway being that you need to take action now to prevent becoming a victim of the automatic password hacking machine epidemic."

He blames 'password laziness and reuse', with only 6% (1,143,815,266) of the 19 billion being unique. When you realize 94% of these passwords were reused across accounts and services, it shows why cybercriminals are likely rubbing their hands right now.

Added to this, 42% of the passwords were said to be in the short range of 8-10 characters in length, while 27% consisted of only lowercase letters and digits without special characters or mixed case.

Cybernews information and security researcher Neringa Macijauskaitė said: "The default password problem remains one of the most persistent and dangerous patterns in leaked credential datasets."

We all know about the passwords that are most commonly used, with the breach showing 53 million uses of 'admin' and a baffling 56 million users of 'password'.

Macijauskaitė added: "Attackers, too, prioritize them, making these passwords among the least secure."

It's easier than ever for hackers to get into your personal details (boonchai wedmakawand / Getty)
It's easier than ever for hackers to get into your personal details (boonchai wedmakawand / Getty)

We're also told never to reuse passwords across multiple platforms. While it might be a faff to try and remember unique passwords for each individual service, considering how many we have these days, Macijauskaitė concluded: "If you reuse passwords across multiple platforms, a breach in one system can compromise the security of other accounts, creating a domino effect

“Attackers constantly harvest the latest credential dumps from exposed info-stealers and recently cracked hashes available publicly.

"These fresh datasets enable waves of highly effective credential-stuffing attacks, often bypassing traditional security defenses."

In terms of where we're being targeted, Paul Walsh, CEO of MetaCert and co-founder of the W3C Mobile Web Initiative in 2004, reiterated that the latest national SMS phishing test carried out by MetaCert showed that the likes of T&T, Verizon, and T-Mobile failed to stop phishing messages from being delivered.

Walsh has written an open letter explaining: "The cybersecurity industry has no shortage of experts in email security, endpoint protection, or network defense, but when it comes to SMS infrastructure and security, there is a distinct lack of deep expertise."

It seems that our smartphones are the latest to be targeted by hackers, so don't click any of those unknown links and send your passwords out into the world.

Choose your content:

11 hours ago
12 hours ago
15 hours ago
17 hours ago
  • Instagram / Savannah Guthire
    11 hours ago

    Leaked Nancy Guthrie ransom note reveals kidnapper's $4,000,000 Bitcoin demand

    The note was sent just days after Guthrie disappeared from her home in February 2026

    News
  • SONNY TUMBELAKA / Contributor via Getty
    12 hours ago

    Google Pixel fans are completely roasting Elon Musk's rumored Starlink phone

    Google fans were quick to point out an awkward problem

    News
  • Feifei Cui-Paoluzzo via Getty
    15 hours ago

    Millions of smartphones just blasted an official 'alien invasion' warning at 1:30 AM

    The alerts triggered an understandable panic

    News
  • Spencer Platt / Staff via Getty
    17 hours ago

    How Elon Musk's $350,000,000,000 loss will affect his trillionaire status

    Musk’s record fortune has taken its first major hit

    News
  • OpenAI issues warning as users' names, addresses and locations are leaked in major breach
  • Experts reveal kitchen gadget owned by millions could be spying on you
  • Experts reveal the terrifying domino effect if GPS suddenly stopped working worldwide
  • FBI warns AI scams are becoming more dangerous after Americans lost almost $900 million