Happy birthday @haveibeenpwned.com! 11 years today, and now with its very own Bluesky account 😊 www.troyhunt.com/introducing-...
It finally happened - I got phished. Impact is limited to the Mailchimp mailing list for my blog, brief blog post with details here and more to come later: www.troyhunt.com/a-sneaky-phi...
This is such cool analysis of PIN in @haveibeenpwned.com's Pwned Passwords. Scroll through the page and watch the heat map change alongside the explanations of how people are creating (somewhat) predictable PINs: www.abc.net.au/news/2025-01...
Great outcome by our global law enforcement partners, that's some big numbers: "at least 40,000 phishing domains linked to LabHost, which had some 10,000 users worldwide". Let's make those phished passwords useless, they're now all in @haveibeenpwned.com: www.europol.europa.eu/media-press/...
A few years ago, I wrote a book. It was the culmination of my most important posts and the stories behind them. Writing this book also helped keep me sane during insane times, and as of today, I'm giving it away for free 😊 www.troyhunt.com/pwned-the-bo...
This is big - data breach at Discord (or at least at an unnamed third-party): discord.com/press-releas...
Happy birthday @haveibeenpwned.com! 12 years ago today, I pushed out a blog post launching a little data breach search tool, and life changed forever. Reading the post again now, did I get it right? 😎 www.troyhunt.com/introducing-...
I recently had a great meetup with @ncsc.gov.uk largely discussing the importance of passkeys. "I should write up a blog post for normal people", I suggested, then went back to my hotel and got phished 🤦♂️ Finally, here's that blog post: www.troyhunt.com/passkeys-for...
After a gargantuan effort, the all-new @haveibeenpwned.com brand and website is now officially live! www.troyhunt.com/have-i-been-...
Finally, after 11 years and 97 days, @haveibeenpwned.com has a new look! Today, we're "soft launching" the rebrand, that is we're giving everyone a look and welcoming contributions, but you won't see it on any publicly facing assets yet. What do you think? www.troyhunt.com/soft-launchi...
This has been an extraordinary set of data to process: 1.3B unique passwords, 2B unique email addresses (including mine 😭) and almost 3M of our @haveibeenpwned.com subscribers in there. It’s been weeks of processing to get this loaded, and finally, it’s done www.troyhunt.com/2-billion-em...
Occasionally, someone takes issue with me flagging a data breach as "sensitive" such that the email addresses can't be publicly searched because they want to dox the users. That's a *really* bad idea, for many reasons: www.troyhunt.com/who-decides-...
That's a massive milestone - 1,000 breaches processed in @haveibeenpwned.com - and it got me wondering why the service is still needed? But you don't have to look far to see why: www.troyhunt.com/1000-data-br...
As the clock counts down to the deadline the Qantas hackers have threatened to publish their data on, how much will the court injunction actually help the breach victims (which includes me)? www.troyhunt.com/court-injunc...
10 years ago today, I started a pet project with a stupid name. Like all my previous projects, I expected it to scratch an itch and then fail miserably. But Have I Been Pwned didn't do that, not by a long shot. A decade later here we are! 🎂 www.troyhunt.com/a-decade-of-...
We're very happy to help the amazing people at @cern.bsky.social gain greater insights into the impact of data breaches on the work they do. CERN is the first intergovernmental organisation we've onboarded to @haveibeenpwned.com, here's the background: www.troyhunt.com/welcoming-ce...
I'm coming to Switzerland! Join me at the Microsoft Azure Zürich User Group in only a few weeks from now: www.meetup.com/de-DE/micros...
Can you believe it’s ten years to the day since the Ashley Madison data breach hit the news?! It’s still arguably the most impactful, most widely publicised data breach in history. krebsonsecurity.com/2015/07/onli...
It sucked getting phished, but I couldn’t be happier with the community responses and positive outcomes from sharing this experience 😊
We're going full steam ahead on the @haveibeenpwned UX rebuild! Loads of static interfaces are now ready for review in the open source repo here: github.com/haveIBeenPwn...
Yesterday, someone tried to sell an alleged data breach of JB Hi-Fi. The breach was a hoax, and it was dead simple to prove 😊 www.troyhunt.com/you-cant-tru...
I've had this dumb report too many times, and Bruce has finally tipped me over the edge. @haveibeenpwned.com is a real service that looks up email addresses in actual data breaches, but some people don't understand what an email address actually is www.troyhunt.com/why-does-hav...
It’s not a real data breach unless it causes people serious harm. Words to that effect are rife throughout privacy reforms that continue to prioritise the responsible organisation over the impacted individuals www.ashurst.com/en/insights/...
I'm looking for some contacts at companies that provide identity protection services, any followers out there? Further, have you had good experiences with any specific companies? There are some product placement opportunities we're exploring in the updated @haveibeenpwned.com site.