Collection #1 is not a single-company breach, it is a credential-stuffing compilation that leaksear.ch metadata indexes at 2,688,378,345 records containing emails and passwords or password hashes (leaksear.ch metadata). The breach date in the indexing metadata is January 17, 2019, matching public reporting by Troy Hunt that described a roughly 2.7 billion-row set of email and password pairs compiled from thousands of earlier breaches (www.troyhunt.com).
What happened
Security researcher Troy Hunt reported that multiple people pointed him to Collection #1 files hosted on MEGA, later removed, and discussed on a hacking forum. Hunt said the collection contained more than 12,000 files and more than 87GB of data, with the forum post describing thousands of dehashed databases and combo lists, but he also cautioned that the listed source services were not all verified (www.troyhunt.com).
WIRED reported the same incident as a breach-of-breaches: a raw trove of about 2.7 billion rows, cleaned down by Hunt to 772,904,991 unique email addresses and more than 21 million unique passwords. Have I Been Pwned currently lists Collection #1 at 772.9M affected addresses (www.wired.com, haveibeenpwned.com).
What data was exposed
leaksear.ch metadata lists the searchable fields as email, password, and hashedPassword (leaksear.ch metadata). In plain English, the indexed records consist of email addresses paired with plaintext passwords or password hashes, with no additional fields listed in the supplied metadata (leaksear.ch metadata).
Public reporting also described the dataset as credential pairs intended for reuse attacks rather than a leak of financial identifiers, Social Security numbers, or similar identity documents (www.wired.com).
Why this matters
Collection #1 is high-risk because email-password pairs can be used for credential stuffing when people reuse the same password across multiple services. OWASP describes credential stuffing as automated use of stolen username and password pairs against website login forms, which can lead to account takeover when credentials are reused (owasp.org).
For security teams, this dataset is a reason to prioritize password reset workflows for reused credentials, enforce multi-factor authentication, and monitor for abnormal login attempts tied to known exposed emails. Individuals should change any reused passwords, enable MFA where available, and check whether their email or password appears in this leak.
Check your exposure
Vetted researchers and incident-response teams can request access or sign in if they already have access to check this dataset. Searchable pivots for this leak include email, hashed password, and password.