<?xml version="1.0" encoding="UTF-8" standalone="no"?><rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:media="http://search.yahoo.com/mrss/" version="2.0"><channel><title>Troy Hunt's Blog</title><description>Observations, musings and conjecture about the world of software and technology</description><link>https://www.troyhunt.com/</link><image><url>https://www.troyhunt.com/favicon.png</url><title>Troy Hunt</title><link>https://www.troyhunt.com/</link></image><generator>Ghost 6.21</generator><lastBuildDate>Wed, 11 Mar 2026 06:46:05 GMT</lastBuildDate><atom:link href="https://www.troyhunt.com/rss/" rel="self" type="application/rss+xml"/><ttl>60</ttl><item><title><![CDATA[Weekly Update 494]]></title><description><![CDATA[<p><a href="https://report-uri.com/?src=troyhunt.com"><strong>Presently sponsored by:</strong> Report URI: Guarding you from rogue JavaScript! Don’t get pwned; get real-time alerts & prevent breaches #SecureYourSite</a></p><p>Since starting HIBP a dozen and a bit years ago, I&apos;ve loaded an average of one breach every 4.7 days. That&apos;s 959 of them to date, but last week it was five in only two days. That&apos;s a few weeks&apos; worth of</p>]]></description><link>https://www.troyhunt.com/weekly-update-494/</link><guid isPermaLink="false">69af6efa55f90d00011b621c</guid><category><![CDATA[Weekly update]]></category><dc:creator><![CDATA[Troy Hunt]]></dc:creator><pubDate>Tue, 10 Mar 2026 01:29:35 GMT</pubDate><media:content medium="image" url="https://www.troyhunt.com/content/images/2026/03/Splash-Template@1x_1.jpg"/><content:encoded><![CDATA[<p><a href="https://report-uri.com/?src=troyhunt.com"><strong>Presently sponsored by:</strong> Report URI: Guarding you from rogue JavaScript! Don’t get pwned; get real-time alerts & prevent breaches #SecureYourSite</a></p><img src="https://www.troyhunt.com/content/images/2026/03/Splash-Template@1x_1.jpg" alt="Weekly Update 494"><p>Since starting HIBP a dozen and a bit years ago, I&apos;ve loaded an average of one breach every 4.7 days. That&apos;s 959 of them to date, but last week it was five in only two days. That&apos;s a few weeks&apos; worth of breaches in only 48 and a half hours. And that&apos;s the way it tends to be in this industry: flurries of activity followed by periods of silence. I obviously don&apos;t have any control over the cadence of breaches (nor when they begin circulating), which does make for some interesting scheduling challenges. Somewhere amongst responding to those incidents, we manage to do all the other mechanical things required to keep this service running the way it does. Anyway, this week it&apos;s &quot;breachapalooza&quot;, with some behind-the-scenes info on the Odido, KomikoAI, Quitbro, Lovora and Provecho.</p>
<!--kg-card-begin: html-->
<div><div style="width: 170px; display: inline-block; margin-right: 3px;"><a href="https://itunes.apple.com/au/podcast/troy-hunts-weekly-update-podcast/id1176454699?ref=troy-hunt"><img src="https://www.troyhunt.com/content/images/2018/05/Listen-on-Apple-Podcasts.svg" alt="Weekly Update 494"></a></div><div style="width: 175px; display: inline-block; margin-right: 3px;"><a href="https://www.youtube.com/playlist?list=PL7LAAxaabizMAXnJe0s3xjQ30q12EVmjt&amp;ref=troyhunt.com"><img src="https://www.troyhunt.com/content/images/2024/09/Watch-and-Listen-on-YouTube.svg" alt="Weekly Update 494"></a></div><div style="width: 118px; display: inline-block; margin-right: 3px;"><a href="https://open.spotify.com/show/7jMtKFohdrw6qmz8AkLqit?ref=troy-hunt"><img src="https://www.troyhunt.com/content/images/2019/10/spotify.svg" class="kg-image" alt="Weekly Update 494"></a></div><div style="width: 120px; display: inline-block;"><a href="https://omny.fm/shows/troy-hunt-weekly-update/playlists/podcast.rss?ref=troy-hunt"><img src="https://www.troyhunt.com/content/images/2018/07/Download-via-RSS.svg" alt="Weekly Update 494"></a></div><iframe width="100%" height="480" src="https://www.youtube.com/embed/I-XLZhGlZuw" title="YouTube video player" allow="accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture; web-share" referrerpolicy="strict-origin-when-cross-origin" allowfullscreen loading="lazy" spellcheck="false"></iframe></div>
<!--kg-card-end: html-->
]]></content:encoded></item><item><title><![CDATA[Weekly Update 493]]></title><description><![CDATA[<p><a href="https://report-uri.com/?src=troyhunt.com"><strong>Presently sponsored by:</strong> Report URI: Guarding you from rogue JavaScript! Don’t get pwned; get real-time alerts & prevent breaches #SecureYourSite</a></p><p>The Odido breach leaks were towards the beginning during this week&apos;s update. I recorded it the day after the second dump of data had hit, with a third dump coming a few hours later, and a final dump of everything the day after that. From what I hear,</p>]]></description><link>https://www.troyhunt.com/weekly-update-493/</link><guid isPermaLink="false">69a53f033875410001ac16bf</guid><category><![CDATA[Weekly update]]></category><dc:creator><![CDATA[Troy Hunt]]></dc:creator><pubDate>Mon, 02 Mar 2026 07:51:14 GMT</pubDate><media:content medium="image" url="https://www.troyhunt.com/content/images/2026/03/Splash-Template.jpg"/><content:encoded><![CDATA[<p><a href="https://report-uri.com/?src=troyhunt.com"><strong>Presently sponsored by:</strong> Report URI: Guarding you from rogue JavaScript! Don’t get pwned; get real-time alerts & prevent breaches #SecureYourSite</a></p><img src="https://www.troyhunt.com/content/images/2026/03/Splash-Template.jpg" alt="Weekly Update 493"><p>The Odido breach leaks were towards the beginning during this week&apos;s update. I recorded it the day after the second dump of data had hit, with a third dump coming a few hours later, and a final dump of everything the day after that. From what I hear, it dominated the news in the Netherlands, and we sure saw that through the traffic stats. Clearly, the leak cadence was designed for maximum news impact, and it seems to have achieved that. It may not have put any cash in the extortionist&apos;s pockets, but it&apos;s set a very visible precedent and, I suspect, put a massive law enforcement target on them. It&apos;s hard to image leaks of this impact continuing for much longer...</p>
<!--kg-card-begin: html-->
<div><div style="width: 170px; display: inline-block; margin-right: 3px;"><a href="https://itunes.apple.com/au/podcast/troy-hunts-weekly-update-podcast/id1176454699?ref=troy-hunt"><img src="https://www.troyhunt.com/content/images/2018/05/Listen-on-Apple-Podcasts.svg" alt="Weekly Update 493"></a></div><div style="width: 175px; display: inline-block; margin-right: 3px;"><a href="https://www.youtube.com/playlist?list=PL7LAAxaabizMAXnJe0s3xjQ30q12EVmjt&amp;ref=troyhunt.com"><img src="https://www.troyhunt.com/content/images/2024/09/Watch-and-Listen-on-YouTube.svg" alt="Weekly Update 493"></a></div><div style="width: 118px; display: inline-block; margin-right: 3px;"><a href="https://open.spotify.com/show/7jMtKFohdrw6qmz8AkLqit?ref=troy-hunt"><img src="https://www.troyhunt.com/content/images/2019/10/spotify.svg" class="kg-image" alt="Weekly Update 493"></a></div><div style="width: 120px; display: inline-block;"><a href="https://omny.fm/shows/troy-hunt-weekly-update/playlists/podcast.rss?ref=troy-hunt"><img src="https://www.troyhunt.com/content/images/2018/07/Download-via-RSS.svg" alt="Weekly Update 493"></a></div><iframe width="100%" height="480" src="https://www.youtube.com/embed/2StXrdw6ZeE" title="YouTube video player" allow="accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture; web-share" referrerpolicy="strict-origin-when-cross-origin" allowfullscreen loading="lazy" spellcheck="false"></iframe></div>
<!--kg-card-end: html-->
]]></content:encoded></item><item><title><![CDATA[Weekly Update 492]]></title><description><![CDATA[<p><a href="https://report-uri.com/?src=troyhunt.com"><strong>Presently sponsored by:</strong> Report URI: Guarding you from rogue JavaScript! Don’t get pwned; get real-time alerts & prevent breaches #SecureYourSite</a></p><p>The recurring theme this week seems to be around the gap between breaches happening and individual victims finding out about them. It&apos;s tempting to blame this on the corporate victim of the breach (the hacked company), but they&apos;re simultaneously dealing with a criminal intrusion, a ransom</p>]]></description><link>https://www.troyhunt.com/weekly-update-492/</link><guid isPermaLink="false">699cef03269dd60001c9c10d</guid><category><![CDATA[Weekly update]]></category><dc:creator><![CDATA[Troy Hunt]]></dc:creator><pubDate>Tue, 24 Feb 2026 00:38:59 GMT</pubDate><media:content medium="image" url="https://www.troyhunt.com/content/images/2026/02/Splash-Template-1.jpg"/><content:encoded><![CDATA[<p><a href="https://report-uri.com/?src=troyhunt.com"><strong>Presently sponsored by:</strong> Report URI: Guarding you from rogue JavaScript! Don’t get pwned; get real-time alerts & prevent breaches #SecureYourSite</a></p><img src="https://www.troyhunt.com/content/images/2026/02/Splash-Template-1.jpg" alt="Weekly Update 492"><p>The recurring theme this week seems to be around the gap between breaches happening and individual victims finding out about them. It&apos;s tempting to blame this on the corporate victim of the breach (the hacked company), but they&apos;re simultaneously dealing with a criminal intrusion, a ransom demand, and class-action lawyers knocking down their doors. They&apos;re in a lose-lose position: pay the ransom and fuel the criminals whilst still failing to escape regulatory disclosure obligations. Disclose early and transparently to individuals, which then provides fuel to the lawyers. Try to sweep the whole thing under the rug and risk attracting the ire of customers and regulators alike. It&apos;s a very big mess, and it doesn&apos;t seem to be getting any better.</p>
<!--kg-card-begin: html-->
<div><div style="width: 170px; display: inline-block; margin-right: 3px;"><a href="https://itunes.apple.com/au/podcast/troy-hunts-weekly-update-podcast/id1176454699?ref=troy-hunt"><img src="https://www.troyhunt.com/content/images/2018/05/Listen-on-Apple-Podcasts.svg" alt="Weekly Update 492"></a></div><div style="width: 175px; display: inline-block; margin-right: 3px;"><a href="https://www.youtube.com/playlist?list=PL7LAAxaabizMAXnJe0s3xjQ30q12EVmjt&amp;ref=troyhunt.com"><img src="https://www.troyhunt.com/content/images/2024/09/Watch-and-Listen-on-YouTube.svg" alt="Weekly Update 492"></a></div><div style="width: 118px; display: inline-block; margin-right: 3px;"><a href="https://open.spotify.com/show/7jMtKFohdrw6qmz8AkLqit?ref=troy-hunt"><img src="https://www.troyhunt.com/content/images/2019/10/spotify.svg" class="kg-image" alt="Weekly Update 492"></a></div><div style="width: 120px; display: inline-block;"><a href="https://omny.fm/shows/troy-hunt-weekly-update/playlists/podcast.rss?ref=troy-hunt"><img src="https://www.troyhunt.com/content/images/2018/07/Download-via-RSS.svg" alt="Weekly Update 492"></a></div><iframe width="100%" height="480" src="https://www.youtube.com/embed/nIrMJIz-E1c" title="YouTube video player" allow="accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture; web-share" referrerpolicy="strict-origin-when-cross-origin" allowfullscreen loading="lazy" spellcheck="false"></iframe></div>
<!--kg-card-end: html-->
]]></content:encoded></item><item><title><![CDATA[Weekly Update 491]]></title><description><![CDATA[<p><a href="https://report-uri.com/?src=troyhunt.com"><strong>Presently sponsored by:</strong> Report URI: Guarding you from rogue JavaScript! Don’t get pwned; get real-time alerts & prevent breaches #SecureYourSite</a></p><p>Well, the ESP32 Bluetooth bridge experiment was a complete failure. Not the radios themselves, they&apos;re actually pretty cool, but there&apos;s just no way I could get the Yale locks to be reliably operated by them. At a guess, BLE is a bit too passive to detect</p>]]></description><link>https://www.troyhunt.com/weekly-update-491/</link><guid isPermaLink="false">6993ef7f269dd60001c9c09a</guid><category><![CDATA[Weekly update]]></category><dc:creator><![CDATA[Troy Hunt]]></dc:creator><pubDate>Tue, 17 Feb 2026 05:09:12 GMT</pubDate><media:content medium="image" url="https://www.troyhunt.com/content/images/2026/02/Splash-Template.jpg"/><content:encoded><![CDATA[<p><a href="https://report-uri.com/?src=troyhunt.com"><strong>Presently sponsored by:</strong> Report URI: Guarding you from rogue JavaScript! Don’t get pwned; get real-time alerts & prevent breaches #SecureYourSite</a></p><img src="https://www.troyhunt.com/content/images/2026/02/Splash-Template.jpg" alt="Weekly Update 491"><p>Well, the ESP32 Bluetooth bridge experiment was a complete failure. Not the radios themselves, they&apos;re actually pretty cool, but there&apos;s just no way I could get the Yale locks to be reliably operated by them. At a guess, BLE is a bit too passive to detect state changes, and unless it was awake and communicating, it just had no idea what was happening with the locks. So, I&apos;ve now silenced all lock-related alerts and am focusing on making the wifi network as reliable as possible in the hope the locks actually become responsive. If that doesn&apos;t work, those <a href="https://www.aqarastore.com.au/products/aqara-smart-lock-u400-with-m100-kit?ref=troyhunt.com" rel="noreferrer">Aqara U400s</a> look <em>really</em> sweet...</p>
<!--kg-card-begin: html-->
<div><div style="width: 170px; display: inline-block; margin-right: 3px;"><a href="https://itunes.apple.com/au/podcast/troy-hunts-weekly-update-podcast/id1176454699?ref=troy-hunt"><img src="https://www.troyhunt.com/content/images/2018/05/Listen-on-Apple-Podcasts.svg" alt="Weekly Update 491"></a></div><div style="width: 175px; display: inline-block; margin-right: 3px;"><a href="https://www.youtube.com/playlist?list=PL7LAAxaabizMAXnJe0s3xjQ30q12EVmjt&amp;ref=troyhunt.com"><img src="https://www.troyhunt.com/content/images/2024/09/Watch-and-Listen-on-YouTube.svg" alt="Weekly Update 491"></a></div><div style="width: 118px; display: inline-block; margin-right: 3px;"><a href="https://open.spotify.com/show/7jMtKFohdrw6qmz8AkLqit?ref=troy-hunt"><img src="https://www.troyhunt.com/content/images/2019/10/spotify.svg" class="kg-image" alt="Weekly Update 491"></a></div><div style="width: 120px; display: inline-block;"><a href="https://omny.fm/shows/troy-hunt-weekly-update/playlists/podcast.rss?ref=troy-hunt"><img src="https://www.troyhunt.com/content/images/2018/07/Download-via-RSS.svg" alt="Weekly Update 491"></a></div><iframe width="100%" height="480" src="https://www.youtube.com/embed/gHAhdBwV6lc" title="YouTube video player" allow="accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture; web-share" referrerpolicy="strict-origin-when-cross-origin" allowfullscreen loading="lazy" spellcheck="false"></iframe></div>
<!--kg-card-end: html-->
]]></content:encoded></item><item><title><![CDATA[Weekly Update 490]]></title><description><![CDATA[<p><a href="https://report-uri.com/?src=troyhunt.com"><strong>Presently sponsored by:</strong> Report URI: Guarding you from rogue JavaScript! Don’t get pwned; get real-time alerts & prevent breaches #SecureYourSite</a></p><p>A big &quot;thank you&quot; to everyone who helped me troubleshoot the problem with my &quot;Print Screen&quot; button on the new PC. Try as we all might, none of us could figure out why it refused to bind to SnagIt and instead insisted on dumping the entire</p>]]></description><link>https://www.troyhunt.com/weekly-update-490/</link><guid isPermaLink="false">698920857f56b8000156f880</guid><category><![CDATA[Weekly update]]></category><dc:creator><![CDATA[Troy Hunt]]></dc:creator><pubDate>Mon, 09 Feb 2026 04:19:39 GMT</pubDate><media:content medium="image" url="https://www.troyhunt.com/content/images/2026/02/Splash-Template@1x_1-1.jpg"/><content:encoded><![CDATA[<p><a href="https://report-uri.com/?src=troyhunt.com"><strong>Presently sponsored by:</strong> Report URI: Guarding you from rogue JavaScript! Don’t get pwned; get real-time alerts & prevent breaches #SecureYourSite</a></p><img src="https://www.troyhunt.com/content/images/2026/02/Splash-Template@1x_1-1.jpg" alt="Weekly Update 490"><p>A big &quot;thank you&quot; to everyone who helped me troubleshoot the problem with my &quot;Print Screen&quot; button on the new PC. Try as we all might, none of us could figure out why it refused to bind to SnagIt and instead insisted on dumping the entire collection of screens to a file on the desktop. But an <em>especailly</em> big thanks to the follower who later emailed me with an idea that didn&apos;t work, and followed up with an idea that finally <em>did!</em></p><figure class="kg-card kg-image-card"><img src="https://www.troyhunt.com/content/images/2026/02/image.png" class="kg-image" alt="Weekly Update 490" loading="lazy" width="1498" height="838" srcset="https://www.troyhunt.com/content/images/size/w600/2026/02/image.png 600w, https://www.troyhunt.com/content/images/size/w1000/2026/02/image.png 1000w, https://www.troyhunt.com/content/images/2026/02/image.png 1498w" sizes="(min-width: 720px) 720px"></figure><p>So, yeah, thanks Logitech for making this a real pain in the arse &#x1F926;&#x200D;&#x2642;&#xFE0F;</p>
<!--kg-card-begin: html-->
<div><div style="width: 170px; display: inline-block; margin-right: 3px;"><a href="https://itunes.apple.com/au/podcast/troy-hunts-weekly-update-podcast/id1176454699?ref=troy-hunt"><img src="https://www.troyhunt.com/content/images/2018/05/Listen-on-Apple-Podcasts.svg" alt="Weekly Update 490"></a></div><div style="width: 175px; display: inline-block; margin-right: 3px;"><a href="https://www.youtube.com/playlist?list=PL7LAAxaabizMAXnJe0s3xjQ30q12EVmjt&amp;ref=troyhunt.com"><img src="https://www.troyhunt.com/content/images/2024/09/Watch-and-Listen-on-YouTube.svg" alt="Weekly Update 490"></a></div><div style="width: 118px; display: inline-block; margin-right: 3px;"><a href="https://open.spotify.com/show/7jMtKFohdrw6qmz8AkLqit?ref=troy-hunt"><img src="https://www.troyhunt.com/content/images/2019/10/spotify.svg" class="kg-image" alt="Weekly Update 490"></a></div><div style="width: 120px; display: inline-block;"><a href="https://omny.fm/shows/troy-hunt-weekly-update/playlists/podcast.rss?ref=troy-hunt"><img src="https://www.troyhunt.com/content/images/2018/07/Download-via-RSS.svg" alt="Weekly Update 490"></a></div><iframe width="100%" height="480" src="https://www.youtube.com/embed/mEE0Qht3Zkw" title="YouTube video player" allow="accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture; web-share" referrerpolicy="strict-origin-when-cross-origin" allowfullscreen loading="lazy" spellcheck="false"></iframe></div>
<!--kg-card-end: html-->
]]></content:encoded></item><item><title><![CDATA[Weekly Update 489]]></title><description><![CDATA[<p><a href="https://report-uri.com/?src=troyhunt.com"><strong>Presently sponsored by:</strong> Report URI: Guarding you from rogue JavaScript! Don’t get pwned; get real-time alerts & prevent breaches #SecureYourSite</a></p><p>This week I&apos;m in Hong Kong, and the day after recording, I gave the talk shown in the image above at INTERPOL&apos;s Cybercrime Expert Group. I posted a little about this on Facebook and LinkedIn, but thought I&apos;d expand on what really stuck with</p>]]></description><link>https://www.troyhunt.com/weekly-update-489/</link><guid isPermaLink="false">6982a9dd15b4070001e9e166</guid><category><![CDATA[Weekly update]]></category><dc:creator><![CDATA[Troy Hunt]]></dc:creator><pubDate>Wed, 04 Feb 2026 02:31:18 GMT</pubDate><media:content medium="image" url="https://www.troyhunt.com/content/images/2026/02/Splash-Template@1x_1.jpg"/><content:encoded><![CDATA[<p><a href="https://report-uri.com/?src=troyhunt.com"><strong>Presently sponsored by:</strong> Report URI: Guarding you from rogue JavaScript! Don’t get pwned; get real-time alerts & prevent breaches #SecureYourSite</a></p><img src="https://www.troyhunt.com/content/images/2026/02/Splash-Template@1x_1.jpg" alt="Weekly Update 489"><p>This week I&apos;m in Hong Kong, and the day after recording, I gave the talk shown in the image above at INTERPOL&apos;s Cybercrime Expert Group. I posted a little about this on Facebook and LinkedIn, but thought I&apos;d expand on what really stuck with me after watching other speakers: the effort agencies are putting into cybercrime prevention. It&apos;s very easy for folks to judge law enforcement solely on what they see from the outside, and that&apos;s mostly going after offenders and taking down criminal infrastructure. But the bit I&apos;m increasingly seeing behind the scenes is a push to help kids (the sorts of hackers I usually interact with are teenagers or young adults at most) make better choices when they&apos;re faced with a pathway into cybercrime. The transition from minor offences (game cheats and DDoS&apos;ing) to full-on cybercriminals (hacking and extortion) is very well-known, and intervening at the right time can not only make a difference to the impact of data breaches on all of us, but it can also make a massive difference to these kids&apos; lives. These agencies are underfunded and understaffed compared to the scale of the problem, so making the time to come visit and find some ways to help in our little corner of the data breach world is a no-brainer &#x1F60A;</p>
<!--kg-card-begin: html-->
<div><div style="width: 170px; display: inline-block; margin-right: 3px;"><a href="https://itunes.apple.com/au/podcast/troy-hunts-weekly-update-podcast/id1176454699?ref=troy-hunt"><img src="https://www.troyhunt.com/content/images/2018/05/Listen-on-Apple-Podcasts.svg" alt="Weekly Update 489"></a></div><div style="width: 175px; display: inline-block; margin-right: 3px;"><a href="https://www.youtube.com/playlist?list=PL7LAAxaabizMAXnJe0s3xjQ30q12EVmjt&amp;ref=troyhunt.com"><img src="https://www.troyhunt.com/content/images/2024/09/Watch-and-Listen-on-YouTube.svg" alt="Weekly Update 489"></a></div><div style="width: 118px; display: inline-block; margin-right: 3px;"><a href="https://open.spotify.com/show/7jMtKFohdrw6qmz8AkLqit?ref=troy-hunt"><img src="https://www.troyhunt.com/content/images/2019/10/spotify.svg" class="kg-image" alt="Weekly Update 489"></a></div><div style="width: 120px; display: inline-block;"><a href="https://omny.fm/shows/troy-hunt-weekly-update/playlists/podcast.rss?ref=troy-hunt"><img src="https://www.troyhunt.com/content/images/2018/07/Download-via-RSS.svg" alt="Weekly Update 489"></a></div><iframe width="100%" height="480" src="https://www.youtube.com/embed/VPfFn1dzd4U" title="YouTube video player" allow="accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture; web-share" referrerpolicy="strict-origin-when-cross-origin" allowfullscreen loading="lazy" spellcheck="false"></iframe></div>
<!--kg-card-end: html-->
]]></content:encoded></item><item><title><![CDATA[Weekly Update 488]]></title><description><![CDATA[<p><a href="https://report-uri.com/?src=troyhunt.com"><strong>Presently sponsored by:</strong> Report URI: Guarding you from rogue JavaScript! Don’t get pwned; get real-time alerts & prevent breaches #SecureYourSite</a></p><p>It&apos;s the discussion about <a href="https://x.com/troyhunt/status/2014364014764036126?ref=troyhunt.com" rel="noreferrer">the reaction of some people in the UK regarding their impending social media ban for under 16s</a> that bugged me most. Most noteably was the hand-waving around &quot;the gov is just trying to siphon up all our IDs&quot; and &quot;this means</p>]]></description><link>https://www.troyhunt.com/weekly-update-488/</link><guid isPermaLink="false">69788725fb29df00015981e8</guid><category><![CDATA[Weekly update]]></category><dc:creator><![CDATA[Troy Hunt]]></dc:creator><pubDate>Tue, 27 Jan 2026 09:50:05 GMT</pubDate><media:content medium="image" url="https://www.troyhunt.com/content/images/2026/01/Splash-Template-4.jpg"/><content:encoded><![CDATA[<p><a href="https://report-uri.com/?src=troyhunt.com"><strong>Presently sponsored by:</strong> Report URI: Guarding you from rogue JavaScript! Don’t get pwned; get real-time alerts & prevent breaches #SecureYourSite</a></p><img src="https://www.troyhunt.com/content/images/2026/01/Splash-Template-4.jpg" alt="Weekly Update 488"><p>It&apos;s the discussion about <a href="https://x.com/troyhunt/status/2014364014764036126?ref=troyhunt.com" rel="noreferrer">the reaction of some people in the UK regarding their impending social media ban for under 16s</a> that bugged me most. Most noteably was the hand-waving around &quot;the gov is just trying to siphon up all our IDs&quot; and &quot;this means <em>everyone</em> will have to show ID, not just under 16s&quot;. If only there was another precedent somewhere in the world where precisely this model was rolled... oh - wait! &#x1F428; The way the ban (sorry - &quot;delay&quot;) has been done in Australia isn&apos;t perfect, but it also doesn&apos;t have to be. There are still plenty of under 16s with access so socials, but I do not know of a single adult who had had to show any form of ID or do any age verification whatsoever. So, relax, wait until we know more about how thye&apos;re planning to do it (and the UK gov <em>will</em> be closely looking at the Aussie precedent), and then lose your minds if it&apos;s done totally differently at the expense of <em>everyone&apos;s</em> privacy.</p>
<!--kg-card-begin: html-->
<div><div style="width: 170px; display: inline-block; margin-right: 3px;"><a href="https://itunes.apple.com/au/podcast/troy-hunts-weekly-update-podcast/id1176454699?ref=troy-hunt"><img src="https://www.troyhunt.com/content/images/2018/05/Listen-on-Apple-Podcasts.svg" alt="Weekly Update 488"></a></div><div style="width: 175px; display: inline-block; margin-right: 3px;"><a href="https://www.youtube.com/playlist?list=PL7LAAxaabizMAXnJe0s3xjQ30q12EVmjt&amp;ref=troyhunt.com"><img src="https://www.troyhunt.com/content/images/2024/09/Watch-and-Listen-on-YouTube.svg" alt="Weekly Update 488"></a></div><div style="width: 118px; display: inline-block; margin-right: 3px;"><a href="https://open.spotify.com/show/7jMtKFohdrw6qmz8AkLqit?ref=troy-hunt"><img src="https://www.troyhunt.com/content/images/2019/10/spotify.svg" class="kg-image" alt="Weekly Update 488"></a></div><div style="width: 120px; display: inline-block;"><a href="https://omny.fm/shows/troy-hunt-weekly-update/playlists/podcast.rss?ref=troy-hunt"><img src="https://www.troyhunt.com/content/images/2018/07/Download-via-RSS.svg" alt="Weekly Update 488"></a></div><iframe width="100%" height="480" src="https://www.youtube.com/embed/SKdisZ9S0jo" title="YouTube video player" allow="accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture; web-share" referrerpolicy="strict-origin-when-cross-origin" allowfullscreen loading="lazy"></iframe></div>
<!--kg-card-end: html-->
]]></content:encoded></item><item><title><![CDATA[Weekly Update 487]]></title><description><![CDATA[<p><a href="https://report-uri.com/?src=troyhunt.com"><strong>Presently sponsored by:</strong> Report URI: Guarding you from rogue JavaScript! Don’t get pwned; get real-time alerts & prevent breaches #SecureYourSite</a></p><p>I thought Scott would cop it first when <a href="https://scotthelme.co.uk/what-a-year-of-solar-and-batteries-really-saved-us-in-2025/?ref=troyhunt.com" rel="noreferrer">he posted about what his solar system really cost him last year</a>. &quot;You&apos;re so gonna get that stupid AI-slop response from some people&quot;, I joked. But no, he got <em>other </em>stupid responses instead! <a href="https://infosec.exchange/@troyhunt/115887606042888443?ref=troyhunt.com" rel="noreferrer">And <em>I</em> got the AI-slop</a></p>]]></description><link>https://www.troyhunt.com/weekly-update-487/</link><guid isPermaLink="false">696c96200d1c9b000141ae2c</guid><category><![CDATA[Weekly update]]></category><dc:creator><![CDATA[Troy Hunt]]></dc:creator><pubDate>Sun, 18 Jan 2026 08:43:10 GMT</pubDate><media:content medium="image" url="https://www.troyhunt.com/content/images/2026/01/Splash-Template-3.jpg"/><content:encoded><![CDATA[<p><a href="https://report-uri.com/?src=troyhunt.com"><strong>Presently sponsored by:</strong> Report URI: Guarding you from rogue JavaScript! Don’t get pwned; get real-time alerts & prevent breaches #SecureYourSite</a></p><img src="https://www.troyhunt.com/content/images/2026/01/Splash-Template-3.jpg" alt="Weekly Update 487"><p>I thought Scott would cop it first when <a href="https://scotthelme.co.uk/what-a-year-of-solar-and-batteries-really-saved-us-in-2025/?ref=troyhunt.com" rel="noreferrer">he posted about what his solar system really cost him last year</a>. &quot;You&apos;re so gonna get that stupid AI-slop response from some people&quot;, I joked. But no, he got <em>other </em>stupid responses instead! <a href="https://infosec.exchange/@troyhunt/115887606042888443?ref=troyhunt.com" rel="noreferrer">And <em>I</em> got the AI-slop responses!</a> Draw your own conclusions on those comments, but I find it fascinating that the one thing people would take away from a thoughtful blog post I spent many hours writing to explain how much work I put into privacy is that the illustration was computer-generated. That such feedback aligns with the political leanings of folks on Mastodon is also fascinating, and probably something I should have seen coming. But hey, there&apos;s nothing new about folks popping their heads up to make inane comments where none were needed, and I have a special blog post for just such occasions: <a href="https://www.troyhunt.com/if-you-dont-want-guitar-lessons-stop-following-me/" rel="noreferrer">If You Don&apos;t Want Guitar Lessons, Stop Following Me</a>.</p>
<!--kg-card-begin: html-->
<div><div style="width: 170px; display: inline-block; margin-right: 3px;"><a href="https://itunes.apple.com/au/podcast/troy-hunts-weekly-update-podcast/id1176454699?ref=troy-hunt"><img src="https://www.troyhunt.com/content/images/2018/05/Listen-on-Apple-Podcasts.svg" alt="Weekly Update 487"></a></div><div style="width: 175px; display: inline-block; margin-right: 3px;"><a href="https://www.youtube.com/playlist?list=PL7LAAxaabizMAXnJe0s3xjQ30q12EVmjt&amp;ref=troyhunt.com"><img src="https://www.troyhunt.com/content/images/2024/09/Watch-and-Listen-on-YouTube.svg" alt="Weekly Update 487"></a></div><div style="width: 118px; display: inline-block; margin-right: 3px;"><a href="https://open.spotify.com/show/7jMtKFohdrw6qmz8AkLqit?ref=troy-hunt"><img src="https://www.troyhunt.com/content/images/2019/10/spotify.svg" class="kg-image" alt="Weekly Update 487"></a></div><div style="width: 120px; display: inline-block;"><a href="https://omny.fm/shows/troy-hunt-weekly-update/playlists/podcast.rss?ref=troy-hunt"><img src="https://www.troyhunt.com/content/images/2018/07/Download-via-RSS.svg" alt="Weekly Update 487"></a></div><iframe width="100%" height="480" src="https://www.youtube.com/embed/r9i8zDpIA1s" title="YouTube video player" allow="accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture; web-share" referrerpolicy="strict-origin-when-cross-origin" allowfullscreen loading="lazy"></iframe></div>
<!--kg-card-end: html-->
]]></content:encoded></item><item><title><![CDATA[Weekly Update 486]]></title><description><![CDATA[<p><a href="https://report-uri.com/?src=troyhunt.com"><strong>Presently sponsored by:</strong> Report URI: Guarding you from rogue JavaScript! Don’t get pwned; get real-time alerts & prevent breaches #SecureYourSite</a></p><p>I&#x2019;m in Oslo! Flighty is telling me I&#x2019;ve flown in or out of here 43 times since a visit in 2014 <a href="https://www.troyhunt.com/ndc-2014-vikings-passwords-and/" rel="noreferrer">set me on a new path professionally</a> and, many years later, <a href="https://x.com/troyhunt/status/1601122643998298112?s=61&amp;t=beHN95Zd9G3fQiuO1h_jzA&amp;ref=troyhunt.com" rel="noreferrer">personally</a>. It&#x2019;s special here, like a second home that just feels&#x2026;</p>]]></description><link>https://www.troyhunt.com/weekly-update-486/</link><guid isPermaLink="false">69694e2d0d1c9b000141adc7</guid><category><![CDATA[Weekly update]]></category><dc:creator><![CDATA[Troy Hunt]]></dc:creator><pubDate>Fri, 16 Jan 2026 06:39:10 GMT</pubDate><media:content medium="image" url="https://www.troyhunt.com/content/images/2026/01/Splash-Template-1.jpg"/><content:encoded><![CDATA[<p><a href="https://report-uri.com/?src=troyhunt.com"><strong>Presently sponsored by:</strong> Report URI: Guarding you from rogue JavaScript! Don’t get pwned; get real-time alerts & prevent breaches #SecureYourSite</a></p><img src="https://www.troyhunt.com/content/images/2026/01/Splash-Template-1.jpg" alt="Weekly Update 486"><p>I&#x2019;m in Oslo! Flighty is telling me I&#x2019;ve flown in or out of here 43 times since a visit in 2014 <a href="https://www.troyhunt.com/ndc-2014-vikings-passwords-and/" rel="noreferrer">set me on a new path professionally</a> and, many years later, <a href="https://x.com/troyhunt/status/1601122643998298112?s=61&amp;t=beHN95Zd9G3fQiuO1h_jzA&amp;ref=troyhunt.com" rel="noreferrer">personally</a>. It&#x2019;s special here, like a second home that just feels&#x2026; <a href="https://m.facebook.com/story.php?story_fbid=pfbid02PyWvy8Jr9EAkG7pjNBefryMgfTZuvGNtqyzi4g39Nq3VbQBuSJytSjybrZoEPKSHl&amp;id=588950508&amp;ref=troyhunt.com" rel="noreferrer">right</a>. This week, the business end of things is about the WhiteDate data breach. Seeking a partner along common racial lines isn&#x2019;t unusual, but&#x2026; well&#x2026; WhiteDate is anything but usual. And, just for fun, see if you can pick the thing that garnered the most negative feedback about that blog post this week, I&#x2019;ll feature the discussion in the next vid.</p>
<!--kg-card-begin: html-->
<div><div style="width: 170px; display: inline-block; margin-right: 3px;"><a href="https://itunes.apple.com/au/podcast/troy-hunts-weekly-update-podcast/id1176454699?ref=troy-hunt"><img src="https://www.troyhunt.com/content/images/2018/05/Listen-on-Apple-Podcasts.svg" alt="Weekly Update 486"></a></div><div style="width: 175px; display: inline-block; margin-right: 3px;"><a href="https://www.youtube.com/playlist?list=PL7LAAxaabizMAXnJe0s3xjQ30q12EVmjt&amp;ref=troyhunt.com"><img src="https://www.troyhunt.com/content/images/2024/09/Watch-and-Listen-on-YouTube.svg" alt="Weekly Update 486"></a></div><div style="width: 118px; display: inline-block; margin-right: 3px;"><a href="https://open.spotify.com/show/7jMtKFohdrw6qmz8AkLqit?ref=troy-hunt"><img src="https://www.troyhunt.com/content/images/2019/10/spotify.svg" class="kg-image" alt="Weekly Update 486"></a></div><div style="width: 120px; display: inline-block;"><a href="https://omny.fm/shows/troy-hunt-weekly-update/playlists/podcast.rss?ref=troy-hunt"><img src="https://www.troyhunt.com/content/images/2018/07/Download-via-RSS.svg" alt="Weekly Update 486"></a></div><iframe width="100%" height="480" src="https://www.youtube.com/embed/x_70JYVt8qU" title="YouTube video player" allow="accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture; web-share" referrerpolicy="strict-origin-when-cross-origin" allowfullscreen loading="lazy"></iframe></div>
<!--kg-card-end: html-->
]]></content:encoded></item><item><title><![CDATA[Who Decides Who Doesn’t Deserve Privacy?]]></title><description><![CDATA[<p><a href="https://report-uri.com/?src=troyhunt.com"><strong>Presently sponsored by:</strong> Report URI: Guarding you from rogue JavaScript! Don’t get pwned; get real-time alerts & prevent breaches #SecureYourSite</a></p><p>Remember the Ashley Madison data breach? That was now more than a decade ago, yet it arguably remains the single most noteworthy data breach of all time. There are many reasons for this accolade, but chief among them is that by virtue of the site being expressly designed to facilitate</p>]]></description><link>https://www.troyhunt.com/who-decides-who-doesnt-deserve-privacy/</link><guid isPermaLink="false">6965ee7765f991000136fdc9</guid><category><![CDATA[Have I Been Pwned]]></category><dc:creator><![CDATA[Troy Hunt]]></dc:creator><pubDate>Tue, 13 Jan 2026 11:41:40 GMT</pubDate><media:content medium="image" url="https://www.troyhunt.com/content/images/2026/01/115fdf8e-e209-48f2-81fe-570cde3983d2.png"/><content:encoded><![CDATA[<p><a href="https://report-uri.com/?src=troyhunt.com"><strong>Presently sponsored by:</strong> Report URI: Guarding you from rogue JavaScript! Don’t get pwned; get real-time alerts & prevent breaches #SecureYourSite</a></p><img src="https://www.troyhunt.com/content/images/2026/01/115fdf8e-e209-48f2-81fe-570cde3983d2.png" alt="Who Decides Who Doesn&#x2019;t Deserve Privacy?"><p>Remember the Ashley Madison data breach? That was now more than a decade ago, yet it arguably remains the single most noteworthy data breach of all time. There are many reasons for this accolade, but chief among them is that by virtue of the site being expressly designed to facilitate extramarital affairs, there was massive social stigma attached to it. As a result, we saw some pretty crazy stuff:</p><ol><li><a href="https://www.troyhunt.com/ashley-madison-search-sites-like/" rel="noreferrer">Various websites were stood up to publicly disclose the presence of people in the data and out them as &#x201C;cheaters&#x201D;</a></li><li><a href="https://www.troyhunt.com/heres-what-ashley-madison-members-have/" rel="noreferrer">Churches trawled through the data and contacted the spouses of exposed parishioners</a></li><li><a href="https://www.theguardian.com/technology/2015/aug/19/snp-mp-michelle-thomsons-data-hack-adultury-ashley-madison?ref=troyhunt.com" rel="noreferrer">The media outed noteworthy individuals they searched for in the breach</a></li><li><a href="https://www.theguardian.com/technology/2015/aug/20/radio-hosts-tell-woman-live-on-air-her-husband-had-ashley-madison-account?ref=troyhunt.com" rel="noreferrer">A radio station back home in Australia encouraged listeners to dial in to check if their spouse was in the data</a></li></ol><p>Arguably, we now live in a more privacy-conscious era, one full of acronyms such as <a href="https://gdpr-info.eu/?ref=troyhunt.com" rel="noreferrer">GDPR</a> and <a href="https://oag.ca.gov/privacy/ccpa?ref=troyhunt.com" rel="noreferrer">CCPA</a>, among others, in different parts of the world. The right to be forgotten, the right to erasure, and, indeed, privacy as a fundamental human right feature very differently in 2026 than they did in 2015. But arguably, even back then, the impact of outing someone as a member of the site should have been obvious. It was certainly obvious to me, which is why <a href="https://www.troyhunt.com/heres-how-im-going-to-handle-ashley/" rel="noreferrer">I introduced the concept of a sensitive data breach before the data even went public</a>. HIBP wouldn&#x2019;t show results for this breach publicly because I was concerned about the impact on people being outed. My worst fear was a spouse coming home to find someone having taken their own life, an HIBP search result on the screen in front of their lifeless body.</p><p><a href="https://www.bbc.com/news/technology-34044506?ref=troyhunt.com" rel="noreferrer">People died as a result of the breach</a>. <a href="https://www.frostbecklaw.com/blog/2015/august/lives-changed-forever-after-ashley-madison-infor/?ref=troyhunt.com#~4b787a8c-6b8b-4dc1-8a42-ad971aa08ba4" rel="noreferrer">Marriages ended</a> and lives were turned upside down. <a href="https://www.theguardian.com/tv-and-radio/article/2024/may/14/ashley-madison-netflix-documentary?utm_source=chatgpt.com" rel="noreferrer">People lost their jobs</a>. The human toll of the breach was profound. The decision I made after witnessing this was that if a breach was likely to have serious personal or social consequences for people in there, it would be flagged as sensitive and not publicly searchable.</p><p>The public doxing of members of the service was often justified on a moral basis: &#x201C;adultery is bad, they deserve to be outed&#x201D;. But there are two massive problems with this attitude, and I&#x2019;ll begin with the purpose for which accounts were sometimes made:</p><p>An email address appearing in that breach <em>implied</em> that the person was there to have an extramarital affair because that was literally the catch-phrase of the service: &#x201C;Life is short, have an affair&#x201D;. But the reality was that people were members of the service for many, many different reasons. Have a read of my post titled <a href="https://www.troyhunt.com/heres-what-ashley-madison-members-have/" rel="noreferrer">Here&#x2019;s What Ashley Madison Members Have Told Me</a> and you&#x2019;ll begin to understand how much more nuanced the situation was:</p><ol><li>Single people had joined the service, and later married before the breach occurred</li><li>People who were worried about a cheating spouse joined the service in order to try to catch them</li><li>Accounts were made with some people&#x2019;s names and email addresses without their consent (there are many &#x201C;Barrack Obamas&#x201D; in the data)</li></ol><p>So, should everyone with an email address on Ashley Madison be considered an adulterer? Clearly, no, that completely misses the nuances of what an email address in a data breach really means. But what about the people who <em>were</em> there to have an affair? Well, that brings us to the second problem:</p><p>Our own personal belief systems are not a valid basis for outing people publicly because their belief systems differ. I used more generic terms than &#x201C;extramarital affair&#x201D; or &#x201C;cheating&#x201D; because there are many other data breaches that are flagged as sensitive in HIBP for the very same reason. <a href="https://haveibeenpwned.com/Breach/FurAffinity?ref=troyhunt.com" rel="noreferrer">Fur Affinity</a>, for example: there is a social stigma around furries and outing someone as a member of that community could have negative consequences for them. <a href="https://haveibeenpwned.com/Breach/RosebuttBoard?ref=troyhunt.com" rel="noreferrer">Rosebutt Board</a> is another example: anal fisting is evidently something a bunch of people are into, and equally, I&#x2019;m sure there are many who take a moral objection to it. And finally, to get to the catalyst for this post, <a href="https://haveibeenpwned.com/Breach/WhiteDate?ref=troyhunt.com" rel="noreferrer">WhiteDate</a>: the website that is <em>ostensibly</em> designed for white people to date other white people. Flagging that as sensitive resulted in some unsavoury commentary being directed at me:</p>
<!--kg-card-begin: html-->
<blockquote class="twitter-tweet"><p lang="en" dir="ltr">U are a Nazi end of story</p>&#x2014; &#x1D517;&#x1D525;&#x1D522;&#x2111;&#x1D521;&#x1D526;&#x1D52C;&#x1D531; (@fuckelonsob) <a href="https://twitter.com/fuckelonsob/status/2008477464805134341?ref_src=twsrc%5Etfw&amp;ref=troyhunt.com">January 6, 2026</a></blockquote> <script async src="https://platform.twitter.com/widgets.js" charset="utf-8"></script>
<!--kg-card-end: html-->
<p>Now, I emphasised &#x201C;ostensibly&#x201D; because the more you dig into this breach, the more you find tones of white supremacy and other behaviours that <em>definitely</em> don&#x2019;t align with my personal value system. That societal view doesn&#x2019;t sit well with me, and I think I&#x2019;m safe in saying it wouldn&#x2019;t sit well with most people. Would someone being outed as a member of that service be likely to result in &#x201C;serious personal or social consequences&#x201D;? Yes, and you can see that in the messaging from the same account:</p>
<!--kg-card-begin: html-->
<blockquote class="twitter-tweet" data-conversation="none"><p lang="en" dir="ltr">Context matters. U are literally shielding Nazi hate mongering scoundrels. We can&apos;t doxx white supremacists? <br><br>If ISIS had a dating site &amp; it got breached, would you protect it out of fear of doxxing? No.<br><br>Every database leaked is sensitive in a way.</p>&#x2014; &#x1D517;&#x1D525;&#x1D522;&#x2111;&#x1D521;&#x1D526;&#x1D52C;&#x1D531; (@fuckelonsob) <a href="https://twitter.com/fuckelonsob/status/2008563802040889409?ref_src=twsrc%5Etfw&amp;ref=troyhunt.com">January 6, 2026</a></blockquote> <script async src="https://platform.twitter.com/widgets.js" charset="utf-8"></script>
<!--kg-card-end: html-->
<p>This behaviour is <em>precisely</em> what I don&#x2019;t want HIBP being used for: as a weapon to attack people solely on the basis of their email address being affiliated with a website that has had a data breach. </p><p>Imagine, for a moment, if ISIS <em>did </em>have a dating site and it was breached, should it be flagged as sensitive? Contrary to the comment about &quot;every database leaked is sensitive&quot;, <a href="https://commission.europa.eu/law/law-topic/data-protection/rules-business-and-organisations/legal-grounds-processing-data/sensitive-data/what-personal-data-considered-sensitive_en?ref=troyhunt.com" rel="noreferrer">there is a clear legal definition for sensitive personal information</a> and it includes:</p><blockquote>personal data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs;</blockquote><blockquote>trade-union membership;</blockquote><blockquote>genetic data, biometric data processed solely to identify a human being;</blockquote><blockquote>health-related data;</blockquote><blockquote>data concerning a person&#x2019;s sex life or sexual orientation.</blockquote><p>An ISIS dating website breach would tick many of the boxes above and would therefore constitute a sensitive data breach. That&apos;s not an endorsement of what they stand for; it&apos;s simply a data-processing decision. But there may be a nuance in there which I didn&apos;t see present in the WhiteDate data - what if it contained illegal activity? (Sidenote: for the most part, HIBP is used by people in Western Europe, North America and Australasia, so when I say &quot;illegal&quot;, I&apos;m looking at it through that lens. Clearly, there are parts of the world where our &quot;illegal&quot; is their &quot;normal&quot;, which further complicates how I run a service accessible from every corner of the world.) I had another example recently that went well beyond moral contention and deep into the realm of illegality:</p>
<!--kg-card-begin: html-->
<blockquote class="twitter-tweet"><p lang="en" dir="ltr">New sensitive breach: &quot;AI girlfriend&quot; site Muah[.]ai had 1.9M email addresses breached last month. Data included AI prompts describing desired images, many sexual in nature and many describing child exploitation. 24% were already in <a href="https://twitter.com/haveibeenpwned?ref_src=twsrc%5Etfw&amp;ref=troyhunt.com">@haveibeenpwned</a>. More: <a href="https://t.co/NTXeQZFr2x?ref=troyhunt.com">https://t.co/NTXeQZFr2x</a></p>&#x2014; Have I Been Pwned (@haveibeenpwned) <a href="https://twitter.com/haveibeenpwned/status/1843780415175438817?ref_src=twsrc%5Etfw&amp;ref=troyhunt.com">October 8, 2024</a></blockquote> <script async src="https://platform.twitter.com/widgets.js" charset="utf-8"></script>
<!--kg-card-end: html-->
<p>Of all the different things people can disagree on when it comes to our moral compasses, paedophilia is where we unanimously draw the line. But I still flagged it as sensitive because of the reasons outlined above. Many people using the service were just lonely guys trying to create an AI girlfriend with no prompts around age. There would be email addresses in there that <em>weren&#x2019;t</em> entered by the rightful owner. And then, there are cases like this:</p>
<!--kg-card-begin: html-->
<blockquote class="twitter-tweet"><p lang="en" dir="ltr">That&apos;s a firstname.lastname Gmail address. Drop it into Outlook and it automatically matches the owner. It has his name, his job title, the company he works for and his professional photo, all matched to that AI prompt. <a href="https://t.co/wpXQMBLf3B?ref=troyhunt.com">pic.twitter.com/wpXQMBLf3B</a></p>&#x2014; Troy Hunt (@troyhunt) <a href="https://twitter.com/troyhunt/status/1843821068060111137?ref_src=twsrc%5Etfw&amp;ref=troyhunt.com">October 9, 2024</a></blockquote> <script async src="https://platform.twitter.com/widgets.js" charset="utf-8"></script>
<!--kg-card-end: html-->
<p>I sat there with my wife, looking at the LinkedIn profile that used the same email address as the person who posted that comment. We looked at his photo and at the veneer of professionalism that surrounded him on that site, knowing what he had written in that prompt above. It was repulsive. Further, beyond being solely an affront to our morals, it was clearly illegal. So, I had many conversations with law enforcement agencies around the world and ensured they had access to the data. Involving law enforcement where data sets contain illegal activity is absolutely the right approach here, but equally, not being the vehicle for <em>implying</em> someone&#x2019;s affiliation or beliefs and doxing them publicly without due process is also absolutely the right approach.</p><p>I understand the gut reaction that flagging a breach like WhiteDate as sensitive protects people whom most of us do not like. But a dozen years of running this service have caused me to consider individual privacy and rights literally hundreds of times, and these conclusions aren&#x2019;t arrived at hastily. Imagine for a moment, the possible ramifications for HIBP if the service were used to publicly shame someone as a &quot;Nazi&quot; and that, in turn, had serious real-world consequences for them. Whether that implication was right or not, there are potentially serious ramifications for us that could well leave us unable to operate at all. And, as the Ashley Madison examples show, there are also potentially life-threatening outcomes for individuals.</p><p>I don&apos;t particularly care about one random, anonymous X account making poorly thought-out statements, but the same sentiment has been expressed after loading previous similar breaches, and it deserves a blog post. Equally, <a href="https://www.troyhunt.com/the-ethics-of-running-a-data-breach-search-service/" rel="noreferrer">I&apos;ve written before about why all the other data breaches are publicly searchable</a> and again, that conclusion is not arrived at lightly.</p><p>I&#x2019;ll finish with a note about privacy that relates to my earlier comment about it being a human right. It&apos;s <em>literally</em> a human right under <a href="https://www.un.org/en/about-us/universal-declaration-of-human-rights?ref=troyhunt.com" rel="noreferrer">Article 12 of the Universal Declaration of Human Rights</a>:</p><blockquote>No one shall be subjected to arbitrary interference with his privacy, family, home or correspondence, nor to attacks upon his honour and reputation. Everyone has the right to the protection of the law against such interference or attacks.</blockquote><p>Breaches with legally defined sensitive data will continue to be flagged as sensitive, and breaches with illegal data will continue to be forwarded to law enforcement agencies.</p>]]></content:encoded></item><item><title><![CDATA[Weekly Update 485]]></title><description><![CDATA[<p><a href="https://report-uri.com/?src=troyhunt.com"><strong>Presently sponsored by:</strong> Report URI: Guarding you from rogue JavaScript! Don’t get pwned; get real-time alerts & prevent breaches #SecureYourSite</a></p><p>15 mins and 40 seconds. That&apos;s how long it took to troubleshoot the first tech problem of 2026, and that&apos;s how far you&apos;ll need to skip through this video to hear the audio at normal volume. The problem Scott and I had is analogous</p>]]></description><link>https://www.troyhunt.com/weekly-update-485/</link><guid isPermaLink="false">695df9652d41e900011715dc</guid><category><![CDATA[Weekly update]]></category><dc:creator><![CDATA[Troy Hunt]]></dc:creator><pubDate>Wed, 07 Jan 2026 06:26:04 GMT</pubDate><media:content medium="image" url="https://www.troyhunt.com/content/images/2026/01/Splash-Template.jpg"/><content:encoded><![CDATA[<p><a href="https://report-uri.com/?src=troyhunt.com"><strong>Presently sponsored by:</strong> Report URI: Guarding you from rogue JavaScript! Don’t get pwned; get real-time alerts & prevent breaches #SecureYourSite</a></p><img src="https://www.troyhunt.com/content/images/2026/01/Splash-Template.jpg" alt="Weekly Update 485"><p>15 mins and 40 seconds. That&apos;s how long it took to troubleshoot the first tech problem of 2026, and that&apos;s how far you&apos;ll need to skip through this video to hear the audio at normal volume. The problem Scott and I had is analogous to the troubleshooting so many of us do in our roles day in and day out:</p><ol><li>This should work fine</li><li>It doesn&apos;t work, and I don&apos;t know why</li><li>I did something that seems unrelate,d and now it works</li><li>I still don&apos;t know why</li></ol><p>Anyway, I&apos;ve cleaned up the audio-only version for the podcast, but I can&apos;t change the YouTube version once it&apos;s streamed, so apologies, just pump your volume up for the first quarter hour. And Happy New Year!</p>
<!--kg-card-begin: html-->
<div><div style="width: 170px; display: inline-block; margin-right: 3px;"><a href="https://itunes.apple.com/au/podcast/troy-hunts-weekly-update-podcast/id1176454699?ref=troy-hunt"><img src="https://www.troyhunt.com/content/images/2018/05/Listen-on-Apple-Podcasts.svg" alt="Weekly Update 485"></a></div><div style="width: 175px; display: inline-block; margin-right: 3px;"><a href="https://www.youtube.com/playlist?list=PL7LAAxaabizMAXnJe0s3xjQ30q12EVmjt&amp;ref=troyhunt.com"><img src="https://www.troyhunt.com/content/images/2024/09/Watch-and-Listen-on-YouTube.svg" alt="Weekly Update 485"></a></div><div style="width: 118px; display: inline-block; margin-right: 3px;"><a href="https://open.spotify.com/show/7jMtKFohdrw6qmz8AkLqit?ref=troy-hunt"><img src="https://www.troyhunt.com/content/images/2019/10/spotify.svg" class="kg-image" alt="Weekly Update 485"></a></div><div style="width: 120px; display: inline-block;"><a href="https://omny.fm/shows/troy-hunt-weekly-update/playlists/podcast.rss?ref=troy-hunt"><img src="https://www.troyhunt.com/content/images/2018/07/Download-via-RSS.svg" alt="Weekly Update 485"></a></div><iframe width="100%" height="480" src="https://www.youtube.com/embed/P9CzKV7XYsA" title="YouTube video player" allow="accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture; web-share" referrerpolicy="strict-origin-when-cross-origin" allowfullscreen loading="lazy"></iframe></div>
<!--kg-card-end: html-->
]]></content:encoded></item><item><title><![CDATA[Weekly Update 484]]></title><description><![CDATA[<p><a href="https://report-uri.com/?src=troyhunt.com"><strong>Presently sponsored by:</strong> Report URI: Guarding you from rogue JavaScript! Don’t get pwned; get real-time alerts & prevent breaches #SecureYourSite</a></p><p>I think the start of this week&apos;s video really nailed it for the techies amongst us: shit doesn&apos;t work, you change something random and now shit works and yu have no idea why &#x1F937;&#x200D;&#x2642;&#xFE0F; Such was my audio this week and apoligise to</p>]]></description><link>https://www.troyhunt.com/weekly-update-484/</link><guid isPermaLink="false">694f3abc0a7112000198cbeb</guid><category><![CDATA[Weekly update]]></category><dc:creator><![CDATA[Troy Hunt]]></dc:creator><pubDate>Sun, 28 Dec 2025 09:33:52 GMT</pubDate><media:content medium="image" url="https://www.troyhunt.com/content/images/2025/12/Splash-Template-2.jpg"/><content:encoded><![CDATA[<p><a href="https://report-uri.com/?src=troyhunt.com"><strong>Presently sponsored by:</strong> Report URI: Guarding you from rogue JavaScript! Don’t get pwned; get real-time alerts & prevent breaches #SecureYourSite</a></p><img src="https://www.troyhunt.com/content/images/2025/12/Splash-Template-2.jpg" alt="Weekly Update 484"><p>I think the start of this week&apos;s video really nailed it for the techies amongst us: shit doesn&apos;t work, you change something random and now shit works and yu have no idea why &#x1F937;&#x200D;&#x2642;&#xFE0F; Such was my audio this week and apoligise to those of you watching the video below for the first few mins (although I managed to clean up the audio-only podcast version). Ironically, doing things non-standard at home was intended to iron out the creases before the impending travel so... a week from now when I do this with Scott Helme from Duabi it&apos;ll all be fine! Let&apos;s see &#x1F91E;</p>
<!--kg-card-begin: html-->
<div><div style="width: 170px; display: inline-block; margin-right: 3px;"><a href="https://itunes.apple.com/au/podcast/troy-hunts-weekly-update-podcast/id1176454699?ref=troy-hunt"><img src="https://www.troyhunt.com/content/images/2018/05/Listen-on-Apple-Podcasts.svg" alt="Weekly Update 484"></a></div><div style="width: 175px; display: inline-block; margin-right: 3px;"><a href="https://www.youtube.com/playlist?list=PL7LAAxaabizMAXnJe0s3xjQ30q12EVmjt&amp;ref=troyhunt.com"><img src="https://www.troyhunt.com/content/images/2024/09/Watch-and-Listen-on-YouTube.svg" alt="Weekly Update 484"></a></div><div style="width: 118px; display: inline-block; margin-right: 3px;"><a href="https://open.spotify.com/show/7jMtKFohdrw6qmz8AkLqit?ref=troy-hunt"><img src="https://www.troyhunt.com/content/images/2019/10/spotify.svg" class="kg-image" alt="Weekly Update 484"></a></div><div style="width: 120px; display: inline-block;"><a href="https://omny.fm/shows/troy-hunt-weekly-update/playlists/podcast.rss?ref=troy-hunt"><img src="https://www.troyhunt.com/content/images/2018/07/Download-via-RSS.svg" alt="Weekly Update 484"></a></div><iframe width="100%" height="480" src="https://www.youtube.com/embed/m8Kc86ONxfY" title="YouTube video player" allow="accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture; web-share" referrerpolicy="strict-origin-when-cross-origin" allowfullscreen loading="lazy"></iframe></div>
<!--kg-card-end: html-->
<h2 id="references">References</h2><ol><li><a href="https://www.malwarebytes.com/browserguard?utm_source=troyhunt&amp;utm_medium=referral&amp;utm_campaign=bgreco" rel="noopener">Sponsored by:&#xA0;Malwarebytes Browser Guard blocks phishing, ads, scams, and trackers for safer, faster browsing</a></li></ol>]]></content:encoded></item><item><title><![CDATA[Weekly Update 483]]></title><description><![CDATA[<p><a href="https://report-uri.com/?src=troyhunt.com"><strong>Presently sponsored by:</strong> Report URI: Guarding you from rogue JavaScript! Don’t get pwned; get real-time alerts & prevent breaches #SecureYourSite</a></p><p>Building out an IoT environment is a little like the old Maslow&apos;s Hierarchy of Needs. All the stuff on the top is only any good if all the stuff on the bottom is good, starting with power. This week, I couldn&apos;t even get that right, but</p>]]></description><link>https://www.troyhunt.com/weekly-update-483/</link><guid isPermaLink="false">694631fa0a7112000198cb82</guid><category><![CDATA[Weekly update]]></category><dc:creator><![CDATA[Troy Hunt]]></dc:creator><pubDate>Sat, 20 Dec 2025 06:31:41 GMT</pubDate><media:content medium="image" url="https://www.troyhunt.com/content/images/2025/12/Splash-Template-1.jpg"/><content:encoded><![CDATA[<p><a href="https://report-uri.com/?src=troyhunt.com"><strong>Presently sponsored by:</strong> Report URI: Guarding you from rogue JavaScript! Don’t get pwned; get real-time alerts & prevent breaches #SecureYourSite</a></p><img src="https://www.troyhunt.com/content/images/2025/12/Splash-Template-1.jpg" alt="Weekly Update 483"><p>Building out an IoT environment is a little like the old Maslow&apos;s Hierarchy of Needs. All the stuff on the top is only any good if all the stuff on the bottom is good, starting with power. This week, I couldn&apos;t even get that right, but thankfully, sparky to rescue and ensuite underfloor heating disconnected, and we now have reliable power again. On top of that is the layer that has increasingly been my nemesis - the network. Two days after recording, I&apos;ve just spent the better part of the entire day making a much more concerted effort to adjust channel and power settings on APs, lock clients that don&apos;t move to the APs that make the most sense, and generally just screw around with it until stuff worked. And then I turned off a circuit, turned it back on again, and all hell broke loose &#x1F62D;</p>
<!--kg-card-begin: html-->
<div><div style="width: 170px; display: inline-block; margin-right: 3px;"><a href="https://itunes.apple.com/au/podcast/troy-hunts-weekly-update-podcast/id1176454699?ref=troy-hunt"><img src="https://www.troyhunt.com/content/images/2018/05/Listen-on-Apple-Podcasts.svg" alt="Weekly Update 483"></a></div><div style="width: 175px; display: inline-block; margin-right: 3px;"><a href="https://www.youtube.com/playlist?list=PL7LAAxaabizMAXnJe0s3xjQ30q12EVmjt&amp;ref=troyhunt.com"><img src="https://www.troyhunt.com/content/images/2024/09/Watch-and-Listen-on-YouTube.svg" alt="Weekly Update 483"></a></div><div style="width: 118px; display: inline-block; margin-right: 3px;"><a href="https://open.spotify.com/show/7jMtKFohdrw6qmz8AkLqit?ref=troy-hunt"><img src="https://www.troyhunt.com/content/images/2019/10/spotify.svg" class="kg-image" alt="Weekly Update 483"></a></div><div style="width: 120px; display: inline-block;"><a href="https://omny.fm/shows/troy-hunt-weekly-update/playlists/podcast.rss?ref=troy-hunt"><img src="https://www.troyhunt.com/content/images/2018/07/Download-via-RSS.svg" alt="Weekly Update 483"></a></div><iframe width="100%" height="480" src="https://www.youtube.com/embed/M5eRKlOEhNw" title="YouTube video player" allow="accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture; web-share" referrerpolicy="strict-origin-when-cross-origin" allowfullscreen loading="lazy"></iframe></div>
<!--kg-card-end: html-->
<h2 id="references">References</h2><ol><li><a href="https://1password.com/troyhunt?ref=troyhunt.com" rel="noopener">Sponsored by:&#xA0;1Password Extended Access Management: Secure every sign-in for every app on every device.</a></li></ol>]]></content:encoded></item><item><title><![CDATA[Weekly Update 482]]></title><description><![CDATA[<p><a href="https://report-uri.com/?src=troyhunt.com"><strong>Presently sponsored by:</strong> Report URI: Guarding you from rogue JavaScript! Don’t get pwned; get real-time alerts & prevent breaches #SecureYourSite</a></p><p>Perhaps it&apos;s just the time of year where we all start to wind down a bit, or maybe I&apos;m just tired after another massive 12 months, but this week&apos;s vid is <em>way</em> late. Ok, going away to the place that had just been breached</p>]]></description><link>https://www.troyhunt.com/weekly-update-482/</link><guid isPermaLink="false">6941de3a0a7112000198cb12</guid><category><![CDATA[Weekly update]]></category><dc:creator><![CDATA[Troy Hunt]]></dc:creator><pubDate>Tue, 16 Dec 2025 22:52:14 GMT</pubDate><media:content medium="image" url="https://www.troyhunt.com/content/images/2025/12/Splash-Template@1x_1-1.jpg"/><content:encoded><![CDATA[<p><a href="https://report-uri.com/?src=troyhunt.com"><strong>Presently sponsored by:</strong> Report URI: Guarding you from rogue JavaScript! Don’t get pwned; get real-time alerts & prevent breaches #SecureYourSite</a></p><img src="https://www.troyhunt.com/content/images/2025/12/Splash-Template@1x_1-1.jpg" alt="Weekly Update 482"><p>Perhaps it&apos;s just the time of year where we all start to wind down a bit, or maybe I&apos;m just tired after another massive 12 months, but this week&apos;s vid is <em>way</em> late. Ok, going away to the place that had just been breached (ironic!) didn&apos;t help, but I think in general the pace we&apos;ve maintained this year just needs to come back a bit. That said, I&apos;ll try to get this week&apos;s and next week&apos;s out on time, then it&apos;s off on travels for the next four weeks after that. Stay tuned for more IoT problems in a few days from now &#x1F926;&#x200D;&#x2642;&#xFE0F;</p>
<!--kg-card-begin: html-->
<div><div style="width: 170px; display: inline-block; margin-right: 3px;"><a href="https://itunes.apple.com/au/podcast/troy-hunts-weekly-update-podcast/id1176454699?ref=troy-hunt"><img src="https://www.troyhunt.com/content/images/2018/05/Listen-on-Apple-Podcasts.svg" alt="Weekly Update 482"></a></div><div style="width: 175px; display: inline-block; margin-right: 3px;"><a href="https://www.youtube.com/playlist?list=PL7LAAxaabizMAXnJe0s3xjQ30q12EVmjt&amp;ref=troyhunt.com"><img src="https://www.troyhunt.com/content/images/2024/09/Watch-and-Listen-on-YouTube.svg" alt="Weekly Update 482"></a></div><div style="width: 118px; display: inline-block; margin-right: 3px;"><a href="https://open.spotify.com/show/7jMtKFohdrw6qmz8AkLqit?ref=troy-hunt"><img src="https://www.troyhunt.com/content/images/2019/10/spotify.svg" class="kg-image" alt="Weekly Update 482"></a></div><div style="width: 120px; display: inline-block;"><a href="https://omny.fm/shows/troy-hunt-weekly-update/playlists/podcast.rss?ref=troy-hunt"><img src="https://www.troyhunt.com/content/images/2018/07/Download-via-RSS.svg" alt="Weekly Update 482"></a></div><iframe width="100%" height="480" src="https://www.youtube.com/embed/LXDI04Q1nbU" title="YouTube video player" allow="accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture; web-share" referrerpolicy="strict-origin-when-cross-origin" allowfullscreen loading="lazy"></iframe></div>
<!--kg-card-end: html-->
<h2 id="references">References</h2><ol><li><a href="https://www.malwarebytes.com/browserguard?utm_source=troyhunt&amp;utm_medium=referral&amp;utm_campaign=bgreco" rel="noreferrer">Sponsored by: Malwarebytes Browser Guard blocks phishing, ads, scams, and trackers for safer, faster browsing</a></li><li><a href="https://x.com/troyhunt/status/1998676312727400692?ref=troyhunt.com" rel="noreferrer">Spicers Retreats suffered a data breach they attributed back to an attack on the Mews reservation platform</a> (timely, given we had a getaway booked there only a couple of days later)</li><li><a href="https://www.troyhunt.com/processing-630-million-more-pwned-passwords-courtesy-of-the-fbi/" rel="noreferrer">We worked through 630 million more passwords provided by the FBI</a> (that includes 46 million we&apos;ve never seen before)</li><li><a href="https://x.com/troyhunt/status/1997126244161540243?ref=troyhunt.com" rel="noreferrer">Hmmm... spam to a Qantas-only email address, wonder where that might have come from?</a> (this should be impossible because there&apos;s an injunction in place &#x1F926;&#x200D;&#x2642;&#xFE0F;)</li></ol>]]></content:encoded></item><item><title><![CDATA[Processing 630 Million More Pwned Passwords, Courtesy of the FBI]]></title><description><![CDATA[<p><a href="https://report-uri.com/?src=troyhunt.com"><strong>Presently sponsored by:</strong> Report URI: Guarding you from rogue JavaScript! Don’t get pwned; get real-time alerts & prevent breaches #SecureYourSite</a></p><p>The sheer scope of cybercrime can be hard to fathom, even when you live and breathe it every day. It&apos;s not just the volume of data, but also the extent to which it replicates across criminal actors seeking to abuse it for their own gain, and to our</p>]]></description><link>https://www.troyhunt.com/processing-630-million-more-pwned-passwords-courtesy-of-the-fbi/</link><guid isPermaLink="false">6938ef22cce4c900013a3d42</guid><category><![CDATA[Have I Been Pwned]]></category><dc:creator><![CDATA[Troy Hunt]]></dc:creator><pubDate>Fri, 12 Dec 2025 21:29:39 GMT</pubDate><media:content medium="image" url="https://www.troyhunt.com/content/images/2025/12/a08fc320-8a40-4fc6-a82e-48a6f12f51ae.png"/><content:encoded><![CDATA[<p><a href="https://report-uri.com/?src=troyhunt.com"><strong>Presently sponsored by:</strong> Report URI: Guarding you from rogue JavaScript! Don’t get pwned; get real-time alerts & prevent breaches #SecureYourSite</a></p><img src="https://www.troyhunt.com/content/images/2025/12/a08fc320-8a40-4fc6-a82e-48a6f12f51ae.png" alt="Processing 630 Million More Pwned Passwords, Courtesy of the FBI"><p>The sheer scope of cybercrime can be hard to fathom, even when you live and breathe it every day. It&apos;s not just the volume of data, but also the extent to which it replicates across criminal actors seeking to abuse it for their own gain, and to our detriment.</p><p>We were reminded of this recently when the FBI reached out and asked if they could send us 630 million more passwords. For the last four years, <a href="https://www.troyhunt.com/open-source-pwned-passwords-with-fbi-feed-and-225m-new-nca-passwords-is-now-live/" rel="noreferrer">they&apos;ve been sending over passwords found during the course of their investigations</a> in the hope that we can help organisations block them from future use. Back then, we were supporting 1.26 <em>billion</em> searches of the service each month. Now, it&apos;s... more:</p>
<!--kg-card-begin: html-->
<div class="twitter-tweet twitter-tweet-rendered" style="display: flex; max-width: 550px; width: 100%; margin-top: 10px; margin-bottom: 10px;"><iframe id="twitter-widget-0" scrolling="no" frameborder="0" allowtransparency="true" allowfullscreen="true" class title="X Post" src="https://platform.twitter.com/embed/Tweet.html?creatorScreenName=troyhunt&amp;dnt=false&amp;embedId=twitter-widget-0&amp;features=eyJ0ZndfdGltZWxpbmVfbGlzdCI6eyJidWNrZXQiOltdLCJ2ZXJzaW9uIjpudWxsfSwidGZ3X2ZvbGxvd2VyX2NvdW50X3N1bnNldCI6eyJidWNrZXQiOnRydWUsInZlcnNpb24iOm51bGx9LCJ0ZndfdHdlZXRfZWRpdF9iYWNrZW5kIjp7ImJ1Y2tldCI6Im9uIiwidmVyc2lvbiI6bnVsbH0sInRmd19yZWZzcmNfc2Vzc2lvbiI6eyJidWNrZXQiOiJvbiIsInZlcnNpb24iOm51bGx9LCJ0ZndfZm9zbnJfc29mdF9pbnRlcnZlbnRpb25zX2VuYWJsZWQiOnsiYnVja2V0Ijoib24iLCJ2ZXJzaW9uIjpudWxsfSwidGZ3X21peGVkX21lZGlhXzE1ODk3Ijp7ImJ1Y2tldCI6InRyZWF0bWVudCIsInZlcnNpb24iOm51bGx9LCJ0ZndfZXhwZXJpbWVudHNfY29va2llX2V4cGlyYXRpb24iOnsiYnVja2V0IjoxMjA5NjAwLCJ2ZXJzaW9uIjpudWxsfSwidGZ3X3Nob3dfYmlyZHdhdGNoX3Bpdm90c19lbmFibGVkIjp7ImJ1Y2tldCI6Im9uIiwidmVyc2lvbiI6bnVsbH0sInRmd19kdXBsaWNhdGVfc2NyaWJlc190b19zZXR0aW5ncyI6eyJidWNrZXQiOiJvbiIsInZlcnNpb24iOm51bGx9LCJ0ZndfdXNlX3Byb2ZpbGVfaW1hZ2Vfc2hhcGVfZW5hYmxlZCI6eyJidWNrZXQiOiJvbiIsInZlcnNpb24iOm51bGx9LCJ0ZndfdmlkZW9faGxzX2R5bmFtaWNfbWFuaWZlc3RzXzE1MDgyIjp7ImJ1Y2tldCI6InRydWVfYml0cmF0ZSIsInZlcnNpb24iOm51bGx9LCJ0ZndfbGVnYWN5X3RpbWVsaW5lX3N1bnNldCI6eyJidWNrZXQiOnRydWUsInZlcnNpb24iOm51bGx9LCJ0ZndfdHdlZXRfZWRpdF9mcm9udGVuZCI6eyJidWNrZXQiOiJvbiIsInZlcnNpb24iOm51bGx9fQ%3D%3D&amp;frame=false&amp;hideCard=false&amp;hideThread=true&amp;id=1979312335056720026&amp;lang=en&amp;origin=https%3A%2F%2Fwww.troyhunt.com%2Finside-the-synthient-threat-data%2F&amp;sessionId=25d6d0c9017915ef93552d11571899883e2c74ca&amp;siteScreenName=troyhunt&amp;theme=light&amp;widgetsVersion=2615f7e52b7e0%3A1702314776716&amp;width=550px" style="position: static; visibility: visible; width: 550px; height: 649px; display: block; flex-grow: 1;" data-tweet-id="1979312335056720026"></iframe></div>
<!--kg-card-end: html-->
<p>Just as it&apos;s hard to wrap your head around the scale of cybercrime, I find it hard to grasp that number fully. On <em>average</em>, that service is hit nearly 7 thousand times per second, and at peak, it&apos;s many times more than that. Every one of those requests is a chance to stop an account takeover. But the real scale goes well beyond the API itself. Because the data model is open source and freely available, many organisations use the <a href="https://github.com/HaveIBeenPwned/PwnedPasswordsDownloader?ref=troyhunt.com" rel="noreferrer">Pwned Passwords Downloader</a> to take the entire corpus offline and query it directly within their own applications. That tool alone calls the API around a million times during download, but the resulting data is then queried&#x2026; well, who knows how many times after that. Pretty cool, right?</p><p>This latest corpus of data came to us as a result of the FBI seizing multiple devices belonging to a suspect. The data appeared to have originated from both the open web and Tor-based marketplaces, Telegram channels and infostealer malware families. We hadn&apos;t seen about 7.4% of them in HIBP before, which might sound small, but that&apos;s 46 million vulnerable passwords we weren&apos;t giving people using the service the opportunity to block. So, we&apos;ve added those and bumped the prevalence count on the other 584 million we already had.</p><p>We&apos;re thrilled to be able to provide this service to the community for free and want to also quickly thank Cloudflare for their support in providing us with the infrastructure to make this possible. Thanks to their edge caching tech, all those passwords are queryable from a location just a handful of milliseconds away from wherever you are on the globe.</p><p>If you&apos;re hitting the API, then all the data is already searchable for you. If you&apos;re downloading it all offline, go and grab the latest data now. Either way, go forth and put it to good use and help make a cybercriminal&apos;s day just that much harder &#x1F60A;</p>]]></content:encoded></item></channel></rss>