Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more

In 2015, attackers exposed more than 13 million records from 000webhost, a free PHP and MySQL hosting service. The dataset included plaintext passwords, making the incident especially risky for anyone who reused a password on another site. The breach was reported to have occurred around March; Troy Hunt published his investigation on 29 October 2015.

What happened in the 000webhost breach?

000webhost suffered a breach that exposed names, email addresses, IP addresses and passwords. Mozilla’s maintained breach record describes more than 13 million affected records. Hunt, a security researcher, wrote that a dataset sent to him was slightly larger than the tipster’s estimate of 13 million; the available sources do not establish one reconciled exact count.

The incident record says the data had been sold and traded before 000webhost was alerted in October 2015. The incident is historical: it does not, by itself, establish the security or current operating status of any service today.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

When did the breach happen, and when did it become public?

  • Approximately March 2015: Mozilla’s breach record dates the incident to around March.
  • Around October 2015: Hunt says he received an anonymous tip about a database dump reportedly taken about five months earlier. He inspected the dataset and confirmed it contained plaintext passwords.
  • 29 October 2015: Hunt published his account of the incident.

The reported breach date and the date of public disclosure are different. Hunt’s account and Mozilla’s record provide the timeline; neither supports treating the precise attack date as certain.

#1 Best Overall
Yubico - YubiKey 5C NFC - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified - Protect Your Online Accounts
  • POWERFUL SECURITY KEY: The YubiKey 5C NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5C NFC secures 100+ of your favorite accounts, including email, password managers, and more
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5C NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
  • PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts

What information was exposed?

The reported data included names, email addresses, IP addresses and passwords. Hunt confirmed that the passwords in the dataset he examined were stored in plaintext: they were readable rather than protected by password hashing. This meant someone with access to the stolen data could read those passwords directly, instead of first having to crack password hashes.

Mozilla’s record describes more than 13 million exposed records. Hunt characterized the dataset he received only as a little larger than 13 million, so a more precise count is not established by these accounts.

Rank #2
Yubico - Security Key C NFC - Basic Compatibility - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.

How did attackers reportedly get in?

A peer-reviewed 2020 case study retrospectively attributes the attack to a web-application vulnerability involving an old PHP version, which led to theft of a database containing email addresses and unencrypted passwords. That is the case study’s account of the entry point; it is not independently verified here by an original 000webhost announcement.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Why could the exposed passwords affect other accounts?

When people reuse passwords, a password stolen from one service may also unlock accounts elsewhere. A 2020 peer-reviewed case study connects reused 000webhost credentials to access to a Zomato developer’s GitHub account during a separate 2017 incident. The account access exposed source code and contributed to that later breach; it is inaccurate to describe the 000webhost incident as a direct attack on Zomato’s servers.

Rank #3
Yubico - YubiKey 5 NFC - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-A or NFC, FIDO Certified - Protect Your Online Accounts
  • POWERFUL SECURITY KEY: The YubiKey 5 NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 NFC secures 100+ of your favorite accounts, including email, password managers, and more
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
  • PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts

What should you do if you reused a password?

  1. Identify every account that used the same password. Include accounts where you made a small variation on the exposed password.
  2. Change each reused password. Set a different, unique password for every account, starting with email, financial, and other accounts that can reset or control additional services.
  3. Check account security settings. Review recovery email addresses, phone numbers, active sessions, and recent sign-in activity where those options are available. Sign out sessions you do not recognize and remove unfamiliar recovery details.
  4. Use breach lookup cautiously. Hunt’s 2015 account describes Have I Been Pwned as a free breach lookup and notification service. A lookup can help identify exposure, but it cannot undo it or prove that an account is safe.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Sources and scope

The sources establish a historical breach and the risks associated with plaintext storage and password reuse. They do not establish 000webhost’s current operating status or ownership.

Best Value
Sale
Thetis Nano-A FIDO2 Security Key Hardware Passkey Device with USB Type A, TOTP/HOTP, FIDO2.0 Two Factor Authentication 2FA MFA, Works with Windows/mac/iOS/Android/Linux/Gmail/Facebook/GitHub/Coinbase
  • Ultra-Compact FIDO2 Security Key - Plug-and-stay or carry on a keychain. This USB-A hardware security key offers portable, always-on protection for desktop and mobile use. (Item Size: 0.75 X 0.74 IN x 0.25 IN)
  • USB-A Hardware Key for All Devices - Works with USB-A ports on PC, Mac, Android, and other laptop/notebook device. Enables secure, cross-platform login with FIDO2.0 passkey support.
  • FIDO Certified Security Key - Meets FIDO and FIDO2 standards. Works with Google, Microsoft, GitHub, Dropbox, and more. Please check service compatibility before purchase.
  • Passwordless Login with Passkey - Supports passkey login via WebAuthn and CTAP2. Enjoy password-free sign-ins where supported. Not all websites or services currently support passkeys.
  • Advanced Multi-Factor Authentication - Offers 200 FIDO2 passkey slots and 50 OATH-TOTP slots. Strong, flexible 2FA/MFA support across various apps and authentication platforms.
Rank #4
Yubico - Security Key NFC - Basic Compatibility - Multi-Factor Authentication (MFA) Key, Connect via USB-A or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key NFC via USB-A and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.