Close Menu
Xarkas BlogXarkas Blog
    What's Hot

    Mivi First Smartphone is Arriving in India on September 24: Snapdragon Chipset & Gemini Support Confirmed

    September 6, 2026

    ColorOS 17 Based on Android 17 Launching on September 17 Alongside OPPO Find X10 Series: Check New Features

    September 6, 2026

    Vivo V80 Lite 5G with 10,000mAh Battery, 1.5K OLED Display, MediaTek Dimensity 7300e, IP69 Rating Launched Globally

    September 6, 2026
    Facebook X (Twitter) Instagram
    Xarkas BlogXarkas Blog
    • Tech News

      Hummer EV Price in India 2026: Complete Guide, Features, Specifications & Availability

      April 2, 2026

      Apple Vision Pro vs Meta Quest 3: The Ultimate VR Headset Showdown

      December 3, 2025

      ChatGPT told them they were special — their families say it led to tragedy

      November 24, 2025

      Beehiiv’s CEO isn’t worried about newsletter saturation

      November 24, 2025

      TechCrunch Mobility: Searching for the robotaxi tipping point

      November 24, 2025
    • Mobiles

      Mivi First Smartphone is Arriving in India on September 24: Snapdragon Chipset & Gemini Support Confirmed

      September 6, 2026

      ColorOS 17 Based on Android 17 Launching on September 17 Alongside OPPO Find X10 Series: Check New Features

      September 6, 2026

      Vivo V80 Lite 5G with 10,000mAh Battery, 1.5K OLED Display, MediaTek Dimensity 7300e, IP69 Rating Launched Globally

      September 6, 2026

      I Used the Google Pixel 10 Pro for a Year, and I Still Can’t Figure It Out

      September 5, 2026

      POCO X8, X8 Power Launched in India With Up to 10,000mAh Battery, 100W Charging

      September 5, 2026
    • Gaming

      Krafton doubles down on India with another $250M bet beyond gaming

      September 5, 2026

      That fake Grand Theft Auto VI demo is actually just malware

      August 26, 2026

      Meta brings Pocket, an app that lets you vibe-code and share games, to US users

      August 21, 2026

      2025’s most downloaded game, Block Blast!, is going ad-free on Apple Arcade

      August 11, 2026

      Amazon is bringing games to Prime Video

      July 23, 2026
    • SEO Tips
    • PC/ Laptops

      Dell Pro 14 (AMD Ryzen AI 7 Pro 350) Review: The Sensible Choice for Everyday Office Work

      January 9, 2026

      CES 2026: MSI Unveils New Prestige, Raider, Stealth and Crosshair Laptops with Intel Core Ultra SoCs

      January 7, 2026

      CES 2026: Samsung Unveils New Galaxy Book6 Laptops

      January 6, 2026

      CES 2026: HP Shows a Keyboard-Based PC and New EliteBooks

      January 6, 2026

      CES 2026: Intel Unveils Core Ultra Series 3, Its First Platform Built on 18A

      January 6, 2026
    • EV

      Hummer EV Price in India 2026: Complete Guide, Features, Specifications & Availability

      April 2, 2026

      Here’s How Much It Costs

      November 15, 2025

      Sodium-Ion Batteries Have Landed In America. The Hard Part Starts Now

      November 15, 2025

      Mazda Begins Testing Its Long-Overdue U.S. EV

      November 14, 2025

      Volkswagen Adds Smartwatch Support For U.S. Vehicles

      November 14, 2025
    • Gadget
    • AI
    Facebook
    Xarkas BlogXarkas Blog
    Home - Featured - Mint Explainer | 16 billion passwords: How bad is the ‘world’s largest data breach’?
    Featured

    Mint Explainer | 16 billion passwords: How bad is the ‘world’s largest data breach’?

    KavishBy KavishJune 23, 2025No Comments5 Mins Read
    Facebook Twitter Pinterest Telegram LinkedIn Tumblr WhatsApp Email
    Mint Explainer | 16 billion passwords: How bad is the ‘world’s largest data breach’?
    Share
    Facebook Twitter LinkedIn Pinterest Telegram Email


    Table of Contents

    Toggle
    • What really happened in the alleged data breach?
    • Is such a widespread data breach even possible?
    • What should users do in this regard?
    • Can attackers still leverage the information?
    • Will companies handle damages and fallouts, if any?

    What really happened in the alleged data breach?

    Cybersecurity researchers that Mint spoke with said that the breaches in question were not strictly new or a single consolidated breach, as early reports had claimed. Instead, the new databases are more like master databases where breached information gathered over almost the past decade was put together by an unidentified group or entity.

    To put it simply, data breaches occur from either unsecured online databases that cyber criminals scrape to collect information, or as part of cyber attacks on large online platforms that lead to the leakage of sensitive information. The largest known data breach so far occurred in 2016, when cyber attackers breached the entire database of once-search and mail giant Yahoo—stealing over 3 billion passwords and related user credentials at one go.

    Also read: India’s big AI test is here: Making sovereign language models work

    Four cybersecurity researchers that Mint spoke with said that the ‘master’ database with 16 billion passwords and other corresponding data—such as name, email addresses, dates of birth and other personally identifiable information (PII)—is likely a collection of multiple breaches, dating back to 2015.

    Is such a widespread data breach even possible?

    While no number of breaches is outside the realm of possibility, most researchers stated that a single breach exposing such a massive volume of sensitive information at one time is nearly unlikely.

    “There are estimates of over 5.5 billion unique users on the internet. Given that any average individual would have at least two or three emails, plus accounts linked with around 10-15 online services—served by an average of around five unique passwords, an extrapolated hypothesis can be that a breach of 16 billion passwords would likely impact over 40% of all internet users globally. For this to happen in one single coordinated data breach would be akin to all of Europe, Asia and then some more being compromised at one go—which is nearly unthinkable even in today’s cybersecurity climate,” said an independent cybersecurity researcher who closely works with various government departments, requesting anonymity.

    Mint could not independently access the alleged database in question or verify whether the information is updated. However, a scroll through cyber breach tracker Have I Been Pwned by noted cyber security professional and Microsoft regional director for the US, Troy Hunt, signified that passwords that have been in use on Apple, Facebook and Google’s platforms since at least 2018 have not surfaced online in the repository’s list of breached passwords.

    Also read: Sovereign silicon: India targets indigenous 2nm, Nvidia-level GPU by 2030

    To be sure, Have I Been Pwned is a public repository that regularly scrapes dark web databases for leaked passwords, such as the one mentioned here.

    What should users do in this regard?

    Cybersecurity experts stated that, irrespective of whether their passwords appear in breach trackers such as the one cited above, updating passwords once every six months is prudent.

    Heather Adkins, vice-president of security engineering at Google, said that as part of its global endeavours to ramp up cybersecurity, the company is in the process of collaborating with Apple, Microsoft and others in a global ‘Fido Alliance’—which seeks to establish ‘passkeys’ as a standard for login.

    “Passkeys reduce the dependency on passwords, and thus reduce how breaches occur by using the biometric authentication information that is stored on users’ phones and laptops. The benefit here is that attackers cannot breach biometric information even if they want, since they require on-device authentication. Various emails and other logins are steadily shifting to passkeys in this regard,” Adkins said.

    Sidharth Mutreja, cofounder and chief technology officer of homegrown enterprise security consultant Rockladder Technologies, added that a second step is to “enable two-factor authentication.”

    “As a second layer of security, users should always either use one-time password-based additional verification or use authenticator apps to ensure that their accounts and personal information are not breached even if a password is compromised. Additionally, it’s important to ensure that any caller or email sender is personally verified before they are responded to,” he added.

    For now, though, each of the researchers agrees that no user is at “immediate risk of losing access to all of their accounts”—even though initial reports projected widespread risk, unlike what was seen before.

    Can attackers still leverage the information?

    Unfortunately, yes. The presence of such databases means that attackers with deep pockets and ill intent can pay to access such databases and use the information for a wide range of tasks. These include actions such as ‘spear phishing’—where attackers use available information about individuals to closely impersonate a potential acquaintance, and dupe them financially or otherwise.

    Also read: Eye in the sky: India to set up satellites to spy on satellites

    To be sure, such attacks have become common in India in the form of ‘digital arrests’ and originate from such databases. A single, coordinated database could thus be a crucial indirect resource for attackers, even if they do not immediately cause any direct harm to users.

    Will companies handle damages and fallouts, if any?

    Mutreja said that a coordinated database that collates all breached information under one umbrella “could create significant liability for enterprises in terms of securing their own platform with database monitoring tools—and put the onus on consumers to instantly and continuously change their passwords.”

    “There’s no one set law that dictates if a company should be liable for a public database—unless a breach in question directly correlates to a company specifically. In such a case, users can directly raise questions on whether companies should have better protected their data. In this case, though, this does not hold,” he added.

    Apple, Facebook and Google—the three major service providers whose information was a part of the breach as per the original report—have not issued any statements or patches pertaining to a data breach of such stature.



    Source link

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Kavish
    • Website

    Related Posts

    Mivi First Smartphone is Arriving in India on September 24: Snapdragon Chipset & Gemini Support Confirmed

    September 6, 2026

    ColorOS 17 Based on Android 17 Launching on September 17 Alongside OPPO Find X10 Series: Check New Features

    September 6, 2026

    Vivo V80 Lite 5G with 10,000mAh Battery, 1.5K OLED Display, MediaTek Dimensity 7300e, IP69 Rating Launched Globally

    September 6, 2026

    I Used the Google Pixel 10 Pro for a Year, and I Still Can’t Figure It Out

    September 5, 2026

    POCO X8, X8 Power Launched in India With Up to 10,000mAh Battery, 100W Charging

    September 5, 2026

    Motorola Edge 70 Plus Launched at IFA 2026 Alongside Moto Watch Ultra and Swarovski Razr

    September 5, 2026

    Comments are closed.

    Top Reviews
    Editors Picks

    Mivi First Smartphone is Arriving in India on September 24: Snapdragon Chipset & Gemini Support Confirmed

    September 6, 2026

    ColorOS 17 Based on Android 17 Launching on September 17 Alongside OPPO Find X10 Series: Check New Features

    September 6, 2026

    Vivo V80 Lite 5G with 10,000mAh Battery, 1.5K OLED Display, MediaTek Dimensity 7300e, IP69 Rating Launched Globally

    September 6, 2026

    I Used the Google Pixel 10 Pro for a Year, and I Still Can’t Figure It Out

    September 5, 2026
    About Us
    About Us

    Email Us: info@xarkas.com

    Facebook Pinterest
    © 2026 . Designed by Xarkas Technologies.
    • Home
    • Mobiles
    • Privacy Policy

    Type above and press Enter to search. Press Esc to cancel.

    Ad Blocker Enabled!
    Ad Blocker Enabled!
    Our website is made possible by displaying online advertisements to our visitors. Please support us by disabling your Ad Blocker.