Back to Blog
critical severity May 05, 2012 · 3 min read

LinkedIn — 164 Million Accounts, Unsalted SHA-1, Four Years in the Dark (2012)

If you have an account with LinkedIn, here’s what’s now in circulation.

Hacked in 2012, sold in 2016. LinkedIn stored passwords as unsalted SHA-1 and the vast majority were cracked within days of release. The account it protects is the one that names your employer, which is what makes it a spearphishing asset.

A professional profile paired with a cracked password hash

What happened

LinkedIn was breached in 2012. At the time the incident was understood to involve roughly six and a half million password hashes. In May 2016 the true scale emerged when 164,611,595 email addresses and passwords were offered for sale on a dark-market site — by the same seller behind the MySpace listing that appeared in the same wave.

Caught in this breach?
You can’t unleak a breach. You can take away what it’s worth.
Deep Sweep shows you every leak tied to you and exactly what to change. Then it strips your name, address and family off the look-up sites that turn a leaked record into somebody knocking on your door — $29 one-time, includes 30 days of Protection. We write to 582 companies. No subscription to start.
Scan free, then Deep Sweep — $29 →
Not ready yet? Run a free breach check on this email
We’ll check it against 13.1B+ leaked records right now — no account needed. Continuous monitoring & alerts are part of Protection.

The passwords were stored as unsalted SHA-1. The vast majority were cracked within days of the data's release.

Four years of being wrong about the size

Worth sitting with: for four years, everyone involved — LinkedIn, the press, and every user who read the coverage and decided they were fine — operated on a figure that was off by a factor of twenty-five. Anyone who checked in 2013 and concluded they were unaffected had no way to know otherwise.

This is the strongest available argument against treating a breach check as a one-time task. The exposure in 2012 was already 164 million accounts. The knowledge of it arrived in 2016. A person's real risk and their information about that risk can diverge for years, and the divergence is invisible from the inside.

Why a professional account is worth more than a social one

The dataset itself is thin — email addresses and passwords, nothing else. Its value comes from what the account is attached to. A LinkedIn profile publicly states your employer, your job title, your seniority, your colleagues and your career history. The breach supplies the credential; the platform supplies the context, for free, to anyone who looks.

That combination is what business email compromise runs on. An attacker who knows a target's employer, reporting line and role can write a message that survives scrutiny, and an attacker who also has a working password from that person's password family can sometimes skip the message entirely.

Executives and founders carry the sharpest version of this. Their LinkedIn profile is deliberately public and deliberately detailed, because that is the point of it.

The identity-chain implication

Most breaches give an attacker a persona and leave them to work out the human behind it. LinkedIn inverts that: the human is already named, photographed and employed. What the breach adds is a password for that named human — and since password habits persist, a 2012 password is a strong template for a 2026 one.

It is also the cleanest bridge between a professional identity and a personal one, because a great many people registered LinkedIn with the same personal email address they use for everything else.

What to do now

What You Should Do

  1. Assume the 2012 password is public and retire every variant of it still in use — unsalted SHA-1 offered no protection to any password
  2. Check whether you registered LinkedIn with a personal address, since that is the link between your professional and personal identities
  3. Enable 2FA on LinkedIn and on the email address behind it
  4. Treat plausible messages referencing your role and colleagues as unverified — your public profile supplies everything needed to write one
  5. Review what your profile discloses beyond your employment: full career history and connections are optional and are what makes targeting cheap

What the free scan actually returns

Sample resultyou@email.comIllustrative — not a real person

Found on people-search siteswe remove these

These listings are live, public, and legal to remove. That’s what a Deep Sweep buys.

value redacted in this sampleage, relatives, address historySpokeo
value redacted in this samplephone, household, property recordsBeenVerified
value redacted in this sample582 companies checked

Found in breach recordsverifiedreported — unverified

Each record is labeled: confirmed breach data, or an attacker’s claim no one has verified.

verifiedvalue redacted in this samplepassword + phone · 2024telecom breach
unverifiedvalue redacted in this sampleclaimed in ransomware listing · 2026leak-site claim

Leaked data cannot be deleted from the internet — anyone claiming otherwise is lying. Broker listings can be removed. We do the second, and show you exactly what to fix from the first.

Were you a LinkedIn customer?
LinkedIn is one breach. Your email is probably in others.
164.6M email addresses accounts were exposed here. Check whether yours is one — and find every other leak tied to the same address, in about 15 seconds. No account, no card.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

Report details & sourcing

Severity Critical
Disclosed May 05, 2012
Last reviewed July 22, 2026
Affected 164.6M email addresses
Data exposed Email addressesPasswords
Editorial & sourcing policy
GalaxyWarden is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data. Breach information is compiled from publicly accessible sources and threat-intelligence platforms, and is reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — see our content & takedown policy or write to support@galaxywarden.com.
Share this Post on X Reddit Email