Skip to main content
  1. Home
  2. Computing
  3. Web
  4. News

Google estimates 1.9 billion usernames are available on the black market

Add as a preferred source on Google

Research carried out by Google in association with the University of California, Berkeley has established that there are 1.9 billion usernames and passwords being traded on the black market. What’s more, as many of 25 percent of these stolen credentials could actually be used to access a legitimate Google account.

The report used Google’s proprietary data to investigate whether or not the pilfered passwords would unlock the door to working accounts, according to Business Insider. Unfortunately, it confirmed that this is definitely the case, reaffirming the importance of proper online security.

Recommended Videos

“Through a combination of password re-use across thousands of online services and targeted collection,” reads the study. “We estimated seven to 25 percent of stolen passwords in our dataset would enable an attacker to log in to a victim’s Google account and thus take over their online identity due to transitive trust.”

This is the danger of using the same password across multiple sites and services — if it’s exposed in one data breach, attackers might be able to combine it with known usernames or email accounts to access various different accounts.

We’ve seen plenty of breaches that left user passwords out in the open in recent years. In 2012, millions of encrypted LinkedIn passwords were leaked to the web, while we’re only just starting to understand the scope of an attack on Yahoo that took place in 2013 — in October, reports circulated that some 3 billion accounts were affected.

The researchers offer up a few different methods that people can use to protect their accounts from unauthorized access. For example, they might use a password manager that creates bespoke entry key for each individual site or service they visit, without them having to remember each one for themselves.

It’s also considered a best practice to employ two-factor authentication, especially for important accounts. This means that anyone gaining access from a new device also needs to provide a code that is typically sent to a smartphone, or an approved email account.

Of course, choosing a secure password is a good start. The top three passwords from plaintext leaks analyzed in this study were ‘123456,’ ‘password,’ and ‘123456789,’ none of which are particularly strong.

Brad Jones
Brad is an English-born writer currently splitting his time between Edinburgh and Pennsylvania. You can find him on Twitter…
I switched from Windows to Mac after 25 years, and it’s the trackpad that converted me.
Well, that rhymes.
Computer, Electronics, Laptop

I’ve been using Windows laptops for almost 25 years. In that time, I never once seriously thought of buying a MacBook. In fact, I can honestly say I had never used one at all until I bought my MacBook Air M5 six months ago. Never borrowed one for a weekend, spent an afternoon at an Apple Store, or even played with one at a friend's house. Macs, to me, were just expensive computers for those who edited videos, made logos, or liked drinking expensive coffee.

My change came completely by accident.

Read more
Apple’s latest refurb drop brings cheaper MacBooks, iPhone 16 Plus, and Apple Watches
More M5 MacBook Air and Pro models are now available through Apple’s refurbished store
Computer, Electronics, Laptop

Apple has added several new MacBook Air and MacBook Pro configurations to its Certified Refurbished Store, alongside more iPhone 16 Plus models and Apple Watches.

The MacBook Air additions arrive at a particularly useful time. New M5 MacBook Air models are currently running in short supply across Apple’s retail network, with some configurations facing delivery estimates stretching into late August or September. Apple also raised MacBook Air prices in June, so students shopping before the new school year are being asked to spend more while potentially waiting longer to get one.

Read more
I didn’t think fake shopping could trick my brain until I tried the viral dopamine websites
On these fake shopping and delivery sites, nothing ever ships or costs a cent, yet the dopamine hit still felt real.
fake-shopping-on-viral-dopamine-websites

I spent some time in the internet's fakest mall, filling a shopping cart with things I could not buy, hunting for discounts on products that do not exist, and checking out three separate times for a grand total of $0.00. Then I placed a fake food order and smoked a cigarette I could not taste, with strangers I will never meet, on a rooftop that does not exist either. My bank balance never changed, but my brain, annoyingly, did.

When I first heard about South Korea's growing "dopamine sites," I assumed they were another internet oddity I would poke around for five minutes and forget by lunch. Instead, I found a surprisingly clever idea hiding beneath the absurdity. You can browse endless imaginary products, add everything to your cart, and complete a purchase that never actually exists. These websites aren't trying to sell you anything. They're trying to recreate the feeling of shopping while removing the part that empties your wallet.

Read more