LinkedIn — 164 Million Accounts, Unsalted SHA-1, Four Years in the Dark (2012)
If you have an account with LinkedIn, here’s what’s now in circulation.
Hacked in 2012, sold in 2016. LinkedIn stored passwords as unsalted SHA-1 and the vast majority were cracked within days of release. The account it protects is the one that names your employer, which is what makes it a spearphishing asset.
What happened
LinkedIn was breached in 2012. At the time the incident was understood to involve roughly six and a half million password hashes. In May 2016 the true scale emerged when 164,611,595 email addresses and passwords were offered for sale on a dark-market site — by the same seller behind the MySpace listing that appeared in the same wave.
The passwords were stored as unsalted SHA-1. The vast majority were cracked within days of the data's release.
Four years of being wrong about the size
Worth sitting with: for four years, everyone involved — LinkedIn, the press, and every user who read the coverage and decided they were fine — operated on a figure that was off by a factor of twenty-five. Anyone who checked in 2013 and concluded they were unaffected had no way to know otherwise.
This is the strongest available argument against treating a breach check as a one-time task. The exposure in 2012 was already 164 million accounts. The knowledge of it arrived in 2016. A person's real risk and their information about that risk can diverge for years, and the divergence is invisible from the inside.
Why a professional account is worth more than a social one
The dataset itself is thin — email addresses and passwords, nothing else. Its value comes from what the account is attached to. A LinkedIn profile publicly states your employer, your job title, your seniority, your colleagues and your career history. The breach supplies the credential; the platform supplies the context, for free, to anyone who looks.
That combination is what business email compromise runs on. An attacker who knows a target's employer, reporting line and role can write a message that survives scrutiny, and an attacker who also has a working password from that person's password family can sometimes skip the message entirely.
Executives and founders carry the sharpest version of this. Their LinkedIn profile is deliberately public and deliberately detailed, because that is the point of it.
The identity-chain implication
Most breaches give an attacker a persona and leave them to work out the human behind it. LinkedIn inverts that: the human is already named, photographed and employed. What the breach adds is a password for that named human — and since password habits persist, a 2012 password is a strong template for a 2026 one.
It is also the cleanest bridge between a professional identity and a personal one, because a great many people registered LinkedIn with the same personal email address they use for everything else.
What to do now
What You Should Do
- Assume the 2012 password is public and retire every variant of it still in use — unsalted SHA-1 offered no protection to any password
- Check whether you registered LinkedIn with a personal address, since that is the link between your professional and personal identities
- Enable 2FA on LinkedIn and on the email address behind it
- Treat plausible messages referencing your role and colleagues as unverified — your public profile supplies everything needed to write one
- Review what your profile discloses beyond your employment: full career history and connections are optional and are what makes targeting cheap
What the free scan actually returns
Found on people-search siteswe remove these
These listings are live, public, and legal to remove. That’s what a Deep Sweep buys.
Found in breach recordsverifiedreported — unverified
Each record is labeled: confirmed breach data, or an attacker’s claim no one has verified.
Leaked data cannot be deleted from the internet — anyone claiming otherwise is lying. Broker listings can be removed. We do the second, and show you exactly what to fix from the first.
Report details & sourcing
Related breaches
MySpace — 360 Million Accounts, and the Weakest Password Storage of Any Major Breach (2008)
MySpace stored the SHA-1 hash of only the first ten characters of your password, lowercased, with no…
Zynga — 173 Million Words With Friends Accounts (2019)
The maker of Words With Friends lost 173 million accounts with salted SHA-1 passwords and, unusually…
Adobe — 153 Million Accounts, and a Password Scheme That Became a Crossword (2013)
Adobe did not hash its passwords. It encrypted them with 3DES in ECB mode, which produces identical …