iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more
The widely reported “1.4 billion leaked passwords” story dates to December 2017. 4iQ said it found a 41 GB collection of 1,400,553,869 username and clear-text-password pairs on an underground forum. That was a compilation of older exposures—not a newly reported breach of one service—and the count was pairs, not unique passwords. The practical risk is password reuse: an old password may still unlock another account.
What was the 1.4 billion-password collection?
In its December 2017 account, security company 4iQ said the collection had last been updated with data inserted on November 29, 2017. It described the database as combining material from 252 previous breaches and known credential lists. Separately, the article described an imported log containing 256 corpuses; those are two descriptions in the same account, not figures that can be reconciled from the available information. 4iQ also said 14% of the exposed pairs had not previously been decrypted by the community. That percentage was the company’s analysis, not a measure of leaked passwords generally. 4iQ’s discovery account is the primary source for these claims, but the figures were not independently audited here.
The headline phrase “1.4 billion passwords” is shorthand. 4iQ’s stated total was 1,400,553,869 credential pairs—each pairing a username with a plain-text password—not that many distinct passwords. The report described a consolidated collection of older exposures, rather than 1.4 billion credentials newly stolen from one company.
Recommended Free Tools
Why can an old leaked password still matter?
Putting known credentials in one searchable collection can make it easier for attackers to try them against accounts elsewhere, a practice known as credential stuffing. The danger is greatest when someone reused the same password on multiple services. NIST says attackers try passwords exposed in earlier breaches, and the FTC explains how reused passwords can give an attacker access to unrelated accounts. NIST’s password guidance and the FTC’s advice for hacked email accounts describe this continuing risk.
#1 Best Overall
- POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
There was contemporaneous disagreement about how much risk repackaging old material added: passwords already known to attackers do not become newly compromised simply because they are collected together, while a searchable consolidation can make them more convenient to use. A CSO opinion article argued for the monitoring-risk view; its author disclosed that he was CEO of VeriClouds. The CSO commentary should be read as that attributed opinion, not as independent verification of the dump.
What to do if you recognize a password
- Change it wherever you used it. Start with your primary email, financial, and work accounts, then replace it on every other account where it appeared. Use a different password for each service.
- Use a password manager for password-based accounts. It can generate and store unique passwords so you do not have to memorize each one. NIST recommends password managers and suggests choosing one that supports MFA. See NIST’s password guidance.
- Turn on a second sign-in protection. Enable MFA where available, or use a passkey if the service offers one. NIST lists authenticator apps, push notifications, text codes, and USB security keys among MFA options and notes that methods differ in security. NIST explains these protections.
- Go directly to the service to make changes. Type its address into your browser or use its official app; do not follow a password-reset link in an unexpected message.
How to check a password without downloading the dump
Do not download or search the leaked collection itself. Use a trusted checker such as Have I Been Pwned’s Pwned Passwords page. HIBP says a password found there should never be used; change it wherever it appears. HIBP’s password checker explains the service and its warning.
Rank #2
- Requires 3 "AAA" batteries (included)
- Unit auto-locks for 30 minutes after 5 consecutive incorrect PINs
HIBP’s API documentation describes a k-anonymity lookup: the checker sends only the first five characters of the password’s hash and compares the returned partial-hash results locally, rather than sending the full password or complete hash. The Pwned Passwords API documentation describes the method. A password not found is not proof that it is safe; HIBP notes that it may simply be absent from the corpus it has indexed.
The Tool Desk
Outbyte PC Repair FREEClear out junk files and repair common Windows errorsFree Scan →Outbyte Driver Updater FREEScan for outdated or missing drivers - takes under a minuteDriver Scan →What is known about the collection today?
The cited incident account establishes what 4iQ reported in 2017. It does not establish whether that exact collection is still circulating or what it contains today. The lasting lesson is about exposed credentials and reuse, not about treating the 2017 report as a new breach: a password exposed years ago can remain a risk if it is still used on another account.
Quick Recap
Rank #4
- FIDO-ONLY FUNCTIONALITY: Supports FIDO2 (passkeys) and FIDO U2F protocols for passwordless and second-factor authentication. Does not support OTP, TOTP, Smart Card (PIV), or other advanced features - upgrade to YubiKey 5 Series for extended functionality
- SECURE AND CONVENIENT: Passwordless MFA login with the YubiKey Bio authenticator and biometric information using a fingerprint, with a PIN as a fallback. Simply plug in via USB and use your fingerprint to authenticate
- DEVICE & OS COMPATIBILITY: Compatible with Windows, macOS, ChromeOS, and Linux. Works seamlessly with supported services like Google and Microsoft accounts, and major password managers. See the full compatibility list at "Works With YubiKey"
- DURABLE & RELIABLE: Resistant to tampering, water, and crushing. No batteries or network connectivity required, offering dependable authentication without any downtime. Securely manufactured in USA & Sweden
- Yubico Authenticator App - Fingerprint enrollment, passkey management and PIN configuration available via the app app - Upgrade to YubiKey 5 Series to generate one-time-passwords (OTP) via Yubico Authenticator and for advanced compatibility (OATH, PIV)
Rank #3
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

