LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

Recent Breaches › LinkedIn Data Breach (2012)

CRITICAL severityConfirmedHow we verify

LinkedIn Data Breach (2012): What Was Exposed & What To Do

RBRecent Breaches Breach Intelligence·May 5, 2012

SourceBreach data provided in part by Have I Been Pwned, used under CC BY 4.0.

LinkedIn Data Breach (2012)

Reported May 5, 2012. Approximately 164.6M people affected.

CRITICAL
Severity
164.6M
People affected
2
Data types exposed
May 5, 2012
Disclosed
ShareXLinkedInFacebookRedditWhatsAppTelegram

The LinkedIn Data Breach (2012) (reported May 5, 2012) exposed Email addresses and Passwords belonging to roughly 164.6M people. If you have an account with them, your information may now be circulating on the open web and with data brokers. Here’s exactly what happened, how to check if you were affected, and what to do next.

Severity & verification
CRITICAL severityConfirmed
Account credentials exposed.
Corroborated by an official disclosure or a verified breach feed.
Was your email in the LinkedIn Data Breach (2012) breach?
164.6M accounts were exposed here. See if yours is one — and every other breach it’s in. 15-sec check, no card.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

In 2012 LinkedIn experienced a security incident in which email addresses and passwords belonging to roughly 164 million accounts were taken. The data stayed out of public view until May 2016, when it was placed for sale on an underground marketplace. For the people whose records were involved, the practical consequence is that professional contact details and login credentials have existed outside the company’s control for several years.

Because the passwords had been stored as unsalted SHA-1 hashes, a large proportion were converted to plain text shortly after the 2016 release. Anyone who reused those passwords on other sites therefore faced an elevated chance that the same credentials could be used elsewhere without their knowledge.

Inside the incident

The incident originated in 2012. At that time an unauthorized party obtained a copy of user email addresses and password hashes from LinkedIn’s systems. The company was notified of the intrusion around May 2012, yet the stolen files did not surface publicly until four years later. In 2016 the data set, containing records for 164.6 million accounts, was offered for sale on a dark-market site. No further technical details about the initial access method or the volume of files removed have been disclosed in public reporting.

How a breach like this happens

Incidents involving the theft of user credentials commonly begin with an attacker obtaining access to an organization’s internal database servers. This access may result from an unpatched vulnerability, compromised administrative credentials, or misconfigured storage. Once inside, the attacker can copy tables that contain email addresses and password hashes. The stolen material is then kept until the holder decides to sell or publish it. When password hashes lack additional protective measures such as salting, automated cracking tools can recover many of the original passwords in a short time after the data becomes available.

Who is LinkedIn?

LinkedIn operates a large professional networking platform used by individuals and organizations to maintain employment histories, contact information, and business relationships. Because the service requires users to supply an email address and create an account password, it routinely stores those two data elements for every registered member. A compromise at a platform of this scale therefore affects a broad population whose professional identities are tied to the exposed records.

What data was at risk

The facts released about the incident identify only two categories of information: email addresses and passwords. The passwords were stored as SHA-1 hashes without salt, and the majority were subsequently cracked after the data appeared in 2016. No additional categories of personal or professional information have been confirmed as part of the released data set. Organizations of this type typically hold further profile details, yet the exact contents beyond the two named fields remain unconfirmed.

What's at stake

For affected individuals the primary concern is that email addresses paired with cracked passwords can be used to attempt access to any other online accounts where the same credentials were reused. This can lead to unauthorized entry into email inboxes, other social or professional services, and any systems that rely on password-only authentication. For the organization, the incident illustrates the long-term consequences of storing password data without modern protective techniques, even when the initial intrusion occurred years earlier.

If your data was in this breach

Begin by changing the password on your LinkedIn account and on any other service where the same password was used. Enable multi-factor authentication wherever it is offered. Review recent login activity on important accounts for signs of unrecognized access. Readers can run a free exposure scan of their email address against known breach data sets to determine whether their information appears in this or other publicly documented incidents.

AICompiled with AI assistance from public sources and published under our editorial standards.

Editorial & sourcing policy
Recent Breaches is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data, and we do not hold the data claimed in leak-site listings. Incidents are compiled from publicly accessible sources and threat-intelligence platforms and are reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — write to support@galaxywarden.com or press@recentbreaches.com.
Check if you’re exposed →

How this breach connects

Company

Method

CompanyLinkedIn security record
65/100
DoxxScan™ · Moderate doxx risk
D 54Poor record

2 reported incidents on record.

See LinkedIn’s full breach history →
RelatedMore incidents at LinkedIn

More recent breaches

Heroes of Newerth Data Breach (2012)December 17, 2012BookCrossing Data Breach (2012)November 5, 2012Netlog Data Breach (2012)November 1, 2012Lookbook Data Breach (2012)August 24, 2012

Latest breaches

Read GalaxyWarden’s full analysis of the LinkedIn Data Breach (2012) →

Verified breach. Breach data provided in part by Have I Been Pwned, used under CC BY 4.0.

Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.

Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.

ShareXLinkedInFacebookRedditWhatsAppTelegram