The Tool Desk
Outbyte PC Repair FREEClear out junk files and repair common Windows errorsFree Scan →Outbyte Driver Updater FREEFix the driver behind crashes, sound loss and screen glitchesFind Drivers →iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more
The Onliner Spambot incident exposed a huge collection of email addresses, passwords and mail-server credentials—not simply a list of addresses stolen from one website. Have I Been Pwned’s current breach index lists 711.5 million affected addresses. If your email appears in the incident, change any password you reused, secure the affected accounts and avoid reset links in unsolicited messages.
What was the Onliner Spambot dump?
On August 28, 2017, security researcher Benkow found an open web server in the Netherlands containing text files with email addresses, passwords and credentials for email servers used to send spam. Mozilla dates the incident to August 28 and says it verified and added the breach record on August 29. HotHardware reported the discovery on August 30, 2017. Mozilla’s Onliner Spambot breach record and HotHardware’s contemporaneous report describe the incident.
The credentials mattered because attackers could use legitimate SMTP mail servers to send spam, making malicious messages harder to distinguish from ordinary mail. The campaign distributed Ursnif banking malware. HotHardware attributed to Benkow an estimate of more than 100,000 infected machines at the time; that is a 2017 estimate, not a current count.
Recommended Free Tools
How many email addresses were exposed?
Have I Been Pwned’s maintained index currently lists Onliner Spambot with 711.5 million affected addresses. That is the database’s current breach count, not proof that 711.5 million unique people had their information newly stolen in a single attack. The dump combined records collected from multiple sources, and an address appearing in it does not by itself identify which service originally exposed the associated information. See the Have I Been Pwned breach index.
#1 Best Overall
Was my email in the 700 million address dump?
Use the official Have I Been Pwned service to check your email address. The service describes itself as a free resource for assessing whether an online account may have been compromised. Enter the address on the service’s site directly; do not follow a link to a checker in a suspicious email.
A result is useful as an exposure warning, not a diagnosis of your current account security. A match means the address was included in the breach data; it does not establish that the password you use today is the same as the exposed one, or that an account is currently being accessed by someone else. A no-match result also cannot guarantee that an account has never been exposed in another incident.
Do I need to change my password?
Change the password for any account where you used a password included in or associated with the exposed credentials, and change it anywhere else you reused that password. Even when you cannot confirm the exact password in the dump, a unique replacement is a prudent step if you reused credentials on accounts tied to the exposed address. Mozilla puts the risk plainly: “Reusing passwords turns a single data breach into many.”
- Start at the service directly. Type its address into your browser or use its official app, then change the password in account or security settings. Avoid unsolicited password-reset links.
- Use a new, unique password. Do not modify the old password with a small variation. Mozilla recommends a passphrase built from unrelated words with numbers and symbols.
- Change every reused login. Prioritize email, financial services and accounts that can reset other passwords, then update any other account that shared the old credential.
- Store the new credentials securely. A reputable password manager can generate and remember a distinct password for each account.
- Review account security. Where available, check recent sign-ins and recovery details, and enable multifactor authentication to add a verification step beyond the password.
Is Onliner Spambot still dangerous?
The incident dates to 2017, and the dump’s existence does not establish that the original campaign is still active today. The lasting concern is that exposed credentials may remain useful if they were reused or never changed. The incident also illustrates how stolen mail-server credentials can help attackers send convincing spam. Treat unexpected attachments, login prompts and password-reset messages cautiously; open the service directly rather than using a link in an unsolicited message.
If you opened an attachment or ran a file from a suspicious message, update your operating system, browser and apps, then use trusted security software to scan the device. Mozilla notes that updates address bugs, vulnerabilities and other security problems. A breach lookup cannot determine whether a particular device is infected.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.What should I do if I reused that password elsewhere?
Change the password on every account that shared it, giving each account a different replacement. Start with your primary email account because access to its inbox may allow password resets for other services. Then secure financial and other high-impact accounts, followed by the rest. If you cannot remember everywhere you reused it, check saved logins in your password manager or browser and work through those accounts.
Quick Recap
Best Value
- Use a password manager to generate and store unique credentials.
- Use multifactor authentication where a service offers it, especially on email and financial accounts.
- Consider an email alias or masking service for sign-ups that do not need your real address. Mozilla recommends email masking as a way to make it harder for hackers or trackers to find and target accounts.
- Keep operating systems, browsers and apps updated.
- Do not provide credentials through links or forms in unexpected emails; navigate to the service yourself.
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.

