• Home
  • News
  • Fortune 500
  • Tech
  • Finance
  • Leadership
  • Lifestyle
  • Rankings
  • Multimedia
TechChanging Face of Security

LinkedIn Lost 167 Million Account Credentials in Data Breach

Robert Hackett
By
Robert Hackett
Robert Hackett
Down Arrow Button Icon
Robert Hackett
By
Robert Hackett
Robert Hackett
Down Arrow Button Icon
May 18, 2016, 12:14 PM ET
Inside LinkedIn Corp. Headquarters Ahead Of Earnings Figures
An employee works on a laptop computer at LinkedIn Corp. headquarters in Mountain View, California, U.S., on Monday, July 28, 2014. LinkedIn Corp. is scheduled to release earnings figures on July 31. Photographer: David Paul Morris/Bloomberg via Getty ImagesPhotograph by David Paul Morris—Bloomberg via Getty Images

Remember LinkedIn’s 2012 data breach?

A hacker stole 6.5 million encrypted passwords from the site and posted them to a Russian crime forum. Now it appears that data theft was just the tip of the iceberg.

A Russian hacker, who goes by “Peace,” is selling 117 million email and password combinations on a dark web marketplace, Vice Motherboard reports. The going rate for the loot is five Bitcoins, or about $2,300.

Get Data Sheet, Fortune’s technology newsletter.

Motherboard said it received a portion of the data—about one million credentials—from Leaked Source, a paid search engine for hacked data that claims to have acquired a total of 167 million of the leaked login credentials. The news outlet verified that at least one of the hacked accounts is legitimate by confirming details with one of the victims.

Cybersecurity researcher Troy Hunt, who runs the hacked data search engine HaveIBeenPwned.com, said he confirmed details with two other victims. He added that he doesn’t yet have a full set to upload to his database yet.

Furthermore, I've only seen a small subset of data (~1M rows), I don't have a full set to load into @haveibeenpwned (yet…)

— Troy Hunt (@troyhunt) May 18, 2016

A person who represents Leaked Source, which has been analyzing the stolen data, told Fortune in an email that 160 million of the compromised accounts have unique email addresses, while the remaining 7 million only include numerical userids and passwords. The spokesperson said that the site’s administrators do not have access to the 6.5 million credentials initially released in 2012, meaning they are unable to check whether they are included as part of the latest set.

“We acquired the 167 million credentials for free from someone who got them from the Russians,” the Leaked Source rep told Fortune. “We have been asked not to reveal who they are or it would jeopardize their relationship with whomever provided it to them.”

For more on LinkedIn, watch:

Cory Scott, LinkedIn’s chief information security officer, published a post addressing the incident on the professional network’s official blog on Wednesday. “Yesterday, we became aware of an additional set of data that had just been released that claims to be email and hashed password combinations of more than 100 million LinkedIn members from that same theft in 2012,” Scott wrote.

He mentioned that the company had required “all accounts we believed to be compromised” to reset their passwords in 2012, and that it recommended all other users else reset their passwords as well. “We are taking immediate steps to invalidate the passwords of the accounts impacted, and we will contact those members to reset their passwords,” he said. “We have no indication that this is as a result of a new security breach.”

Scott added that the site had been encrypting and “salting”—or appending random data to the passwords before they’re encrypted to make them less crackable—”for several years.” Leaked Source noted, however, that the leaked passwords it had obtained were encrypted (with the SHA-1 hashing function), but lacked the “salting” security feature. Presumably, LinkedIn began “salting” their passwords after the 2012 incident.

To stay protected, LinkedIn users should update their passwords on the site (and anywhere else they may have reused the same password online) and also implement two-factor authentication—a feature that sends a security code to a user’s phone upon login.

About the Author
Robert Hackett
By Robert Hackett
Instagram iconLinkedIn iconTwitter icon
See full bioRight Arrow Button Icon

Latest in Tech

Brad Lightcap, chief operating officer of OpenAI, on stage
AIBrainstorm AI
OpenAI COO Brad Lightcap says code red will ‘force’ the company to focus, as the ChatGPT maker ramps up enterprise push
By Beatrice NolanDecember 9, 2025
30 minutes ago
An Optimus robot serving in a restaurant
InnovationElon Musk
Tesla promotes Optimus as its next big breakthrough, but one robot’s collapse has sparked doubts about their current level of autonomy
By Marco Quiroz-GutierrezDecember 9, 2025
2 hours ago
AITech
‘But is that real work? It’s not’ Business leaders still don’t trust AI agents, Harvard survey shows
By Patrick Kulp and Tech BrewDecember 9, 2025
3 hours ago
Sam Altman (left) with Jimmy Fallon
Successthe future of work
Even the man behind ChatGPT, OpenAI CEO Sam Altman, is worried about the ‘rate of change that’s happening in the world right now’ thanks to AI
By Preston ForeDecember 9, 2025
3 hours ago
A close-up of a woman using Google Glass
InnovationGoogle
Google says its first Gemini-powered smart glasses are coming next year. Here’s what they can do
By Dave SmithDecember 9, 2025
4 hours ago
Gen Z engineering apprentice
SuccessGen Z
With millions of Gen Z unemployed globally, the UK is tossing $965 million at the problem to get young people in AI, hospitality, and engineering jobs
By Emma BurleighDecember 9, 2025
4 hours ago

Most Popular

placeholder alt text
Real Estate
The 'Great Housing Reset' is coming: Income growth will outpace home-price growth in 2026, Redfin forecasts
By Nino PaoliDecember 6, 2025
3 days ago
placeholder alt text
Investing
Baby boomers have now 'gobbled up' nearly one-third of America's wealth share, and they're leaving Gen Z and millennials behind
By Sasha RogelbergDecember 8, 2025
1 day ago
placeholder alt text
Success
When David Ellison was 13, his billionaire father Larry bought him a plane. He competed in air shows before leaving it to become a Hollywood executive
By Dave SmithDecember 9, 2025
9 hours ago
placeholder alt text
Success
Craigslist founder signs the Giving Pledge, and his fortune will go to military families, fighting cyberattacks—and a pigeon rescue
By Sydney LakeDecember 8, 2025
1 day ago
placeholder alt text
Uncategorized
Transforming customer support through intelligent AI operations
By Lauren ChomiukNovember 26, 2025
13 days ago
placeholder alt text
Success
‘Godfather of AI’ says Bill Gates and Elon Musk are right about the future of work—but he predicts mass unemployment is on its way
By Preston ForeDecember 4, 2025
5 days ago
Rankings
  • 100 Best Companies
  • Fortune 500
  • Global 500
  • Fortune 500 Europe
  • Most Powerful Women
  • Future 50
  • World’s Most Admired Companies
  • See All Rankings
Sections
  • Finance
  • Leadership
  • Success
  • Tech
  • Asia
  • Europe
  • Environment
  • Fortune Crypto
  • Health
  • Retail
  • Lifestyle
  • Politics
  • Newsletters
  • Magazine
  • Features
  • Commentary
  • Mpw
  • CEO Initiative
  • Conferences
  • Personal Finance
  • Education
Customer Support
  • Frequently Asked Questions
  • Customer Service Portal
  • Privacy Policy
  • Terms Of Use
  • Single Issues For Purchase
  • International Print
Commercial Services
  • Advertising
  • Fortune Brand Studio
  • Fortune Analytics
  • Fortune Conferences
  • Business Development
About Us
  • About Us
  • Editorial Calendar
  • Press Center
  • Work At Fortune
  • Diversity And Inclusion
  • Terms And Conditions
  • Site Map

© 2025 Fortune Media IP Limited. All Rights Reserved. Use of this site constitutes acceptance of our Terms of Use and Privacy Policy | CA Notice at Collection and Privacy Notice | Do Not Sell/Share My Personal Information
FORTUNE is a trademark of Fortune Media IP Limited, registered in the U.S. and other countries. FORTUNE may receive compensation for some links to products and services on this website. Offers may be subject to change without notice.