06/20/2025
This is still a new threat - even if the 16 billion passwords were leaked (Apple, FB, Google) a while back. All tranches have been packaged together and recently spotted on sale in the dark web. This happens more frequently now with infostealer malware being distributed to devices in numerous ways (included in downloads; clicking links in emails and on social media, infected websites; etc.).
It's a good reminder for all of us to reset passwords and use a password manager like 1Password or Bitwarden - the 2 which so far haven't been breached. If not using a password manager, ANY memorable password is highly likely to be guessed by algorithms.
News broke today of a "mother of all breaches," sparking wide media coverage filled with warnings and fear-mongering. However, it appears to be a compilation of previously leaked credentials stolen by infostealers, exposed in data breaches, and via credential stuffing attacks.