LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

Recent Breaches › Naz.API Data Breach (2023)

CRITICAL severityConfirmedHow we verify

Naz.API Data Breach (2023): What Was Exposed & What To Do

RBRecent Breaches Breach Intelligence·September 20, 2023

SourceBreach data provided in part by Have I Been Pwned, used under CC BY 4.0.

Naz.API Data Breach (2023)

Reported September 20, 2023. Approximately 70.8M people affected.

CRITICAL
Severity
70.8M
People affected
2
Data types exposed
September 20, 2023
Disclosed
ShareXLinkedInFacebookRedditWhatsAppTelegram

The Naz.API Data Breach (2023) (reported September 20, 2023) exposed Email addresses and Passwords belonging to roughly 70.8M people. If you have an account with them, your information may now be circulating on the open web and with data brokers. Here’s exactly what happened, how to check if you were affected, and what to do next.

Severity & verification
CRITICAL severityConfirmed
Plaintext passwords exposed.
Corroborated by an official disclosure or a verified breach feed.
Was your email in the Naz.API Data Breach (2023) breach?
70.8M accounts were exposed here. See if yours is one — and every other breach it’s in. 15-sec check, no card.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

Compilations of stolen credentials continue to circulate widely on criminal forums, feeding automated attacks that test reused passwords across countless services. In that landscape, large dumps that mix stealer-log output with credential-stuffing lists remain a persistent source of risk for ordinary internet users.

In September 2023 a collection titled Naz.API, reported as containing more than 100 GB of material and affecting roughly 70.8 million people, was posted to a popular hacking forum. Public reporting describes the corpus as holding tens of millions of unique email addresses paired with passwords, making the incident consequential for anyone whose login details may have been swept into the set.

Inside the incident

According to the reported summary, over 100 GB of stealer logs and credential-stuffing lists titled “Naz.API” appeared on a popular hacking forum in September 2023. The material was described as a combination of email-address and plain-text password pairs that also recorded the service into which the credentials had been entered, together with standalone credential pairs obtained from unnamed sources. The corpus was said to include 71 million unique email addresses and 100 million unique passwords. The incident was reported on 20 September 2023 and is associated with approximately 70.8 million people affected. No further public detail has been given on the precise timing of the underlying thefts, the original intrusion methods, or any single organisation that was the sole source of the data.

How a breach like this happens

Incidents of this type typically begin with information-stealing malware that runs on compromised personal devices. Once installed—often through phishing attachments, malicious downloads or cracked software—the malware harvests saved browser passwords, form-fill data and session tokens and exfiltrates them to the attacker. Separately, credential-stuffing lists are assembled by aggregating earlier breaches and testing the resulting username-password pairs against other sites. Operators then package the raw stealer logs and the stuffing lists into large archives and advertise them on underground forums. Because the material is drawn from many unrelated victims and services, the resulting dump rarely points to a single corporate network compromise; instead it reflects the cumulative leakage of credentials from individual machines and prior incidents. No specific threat group has been attributed in the available facts for the Naz.API posting.

About Naz.API

Naz.API is the title under which the September 2023 collection was released; public reporting treats it as the label for the compiled stealer logs and credential lists rather than as a conventional operating company. Collections of this kind function as wholesale repositories of login data that criminals can search, filter and reuse. Organisations and individuals whose credentials appear inside such archives face elevated risk because the data is already formatted for automated reuse. The presence of service identifiers alongside many of the pairs further increases the practical value of the material to anyone conducting targeted stuffing or account-takeover attempts.

What data was at risk

The facts name email addresses and passwords as the exposed data types. Reporting further states that many records consisted of email-and-plain-text-password pairs accompanied by the service they were entered into, plus additional standalone credential pairs. Exact contents beyond these categories remain unconfirmed in the public record; no other personal-data fields have been listed. In general, stealer-log collections of this nature can also contain whatever else the malware captured on a given device, but only the email addresses and passwords are confirmed here.

The real-world impact

For affected individuals the primary risk is account takeover. Because the passwords appear in plain text, an attacker can attempt immediate login to the original service or to any other site where the same password was reused. Successful takeover can lead to fraudulent transactions, identity misuse, or further compromise of linked accounts. For any organisation whose users appear in the set, the consequence is an increase in credential-stuffing traffic and potential unauthorised access to customer or employee accounts. The scale—tens of millions of unique emails and passwords—means the exposure is broad rather than confined to a single breached company, so the practical burden falls on users to change passwords and on services to detect anomalous logins.

What to do if you're exposed

Change the password on every account that may have used the same or a similar credential, starting with email, banking and any service that holds payment details. Enable multi-factor authentication wherever it is offered. Monitor account statements and login notifications for unfamiliar activity. Consider using a password manager to generate and store unique passwords going forward. Readers can also run a free exposure scan of their email address to check whether their information has surfaced in known breach data and to receive guidance on next steps.

AICompiled with AI assistance from public sources and published under our editorial standards.

Editorial & sourcing policy
Recent Breaches is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data, and we do not hold the data claimed in leak-site listings. Incidents are compiled from publicly accessible sources and threat-intelligence platforms and are reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — write to support@galaxywarden.com or press@recentbreaches.com.
Check if you’re exposed →

How this breach connects

Company

Method

CompanyNaz.API security record
70/100
DoxxScan™ · Moderate doxx risk
C- 64Below-average record

1 reported incident on record.

See Naz.API’s full breach history →

More recent breaches

Hathway Data Breach (2023)December 17, 2023InflateVids Data Breach (2023)December 12, 2023KitchenPal Data Breach (2023)November 14, 2023Facebook Marketplace Data Breach (2023)October 1, 2023

Latest breaches

Read GalaxyWarden’s full analysis of the Naz.API Data Breach (2023) →

Verified breach. Breach data provided in part by Have I Been Pwned, used under CC BY 4.0.

Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.

Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.

ShareXLinkedInFacebookRedditWhatsAppTelegram