Eskenzi PR ad banner Eskenzi PR ad banner
  • About Us
Tuesday, 23 June, 2026
IT Security Guru
Eskenzi PR banner
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
IT Security Guru
No Result
View All Result

71 Million Emails Added to Have I Been Pwned From Naz.API Stolen Account List

Cybersecurity experts from across the industry weigh in on this significant update and advise how best business leaders can protect their organisations.

by Guru Writer
January 19, 2024
in Features
Two computer screens filled with code. Shadowed figure.
Share on FacebookShare on Twitter

Almost 71 million email addresses linked to compromised accounts from the Naz.API dataset have been incorporated into the data breach notification service of Have I Been Pwned.

The Naz.API dataset, consisting of 1 billion credentials, is an extensive compilation derived from credential stuffing lists and data pilfered by information-stealing malware. Credential stuffing lists comprise login name and password pairs obtained from prior data breaches, serving as tools to compromise accounts on different platforms.

According to a blog post written by Troy Hunt, Have I Been Pwned?’s creator, the dataset included 319 files totalling 104GB and 70,840,771 unique email addresses.

Josh Hickling, Principal Consultant at Pentest People, explains why this addition is significant:

“Records that have been added to a database such as this can be concerning, especially if the credentials provide access to a sensitive service. From an impact perspective to the public, it would depend on where the disclosed credentials would provide access to. Attackers would undertake credential stuffing attacks across a variety of online services, i.e. Facebook, Google Mail, Online Banking etc, supplying the disclosed credentials to access whatever may be behind the affected service.”

He continues: “More worryingly, if the credentials are reused across multiple services, it may provide access to several accounts across the internet.”

Paul Bischoff, Consumer Privacy Advocate at Comparitech, says:

“Naz.api is a good example of how cybercriminals can combine data from multiple data breaches and public sources to create detailed profiles of potential victims. Such datasets will will only get bigger and more sophisticated as time goes on, allowing cybercriminals to more effectively find and target victims. In this case, cybercriminals check Naz.api to see if you have any exposed passwords in the database, then use those passwords in credential stuffing attacks on other services.”

Javvad Malik, lead security awareness advocate at KnowBe4, explains why password attacks are common:

“Passwords remain the low hanging fruit for many criminals, hence why password stealing malware is so popular. It gives a good return on investment for those looking to compromise accounts. Which is why it’s important that we don’t just rely on people choosing strong passwords, because if that is compromised, then there’s little protection remaining. Rather, encouraging people to use password managers and implementing MFA across websites is the preferred way to secure accounts. In addition, websites should consider controls that can detect and block password stuffing or brute force attacks to further make it difficult for criminals.”

Chris Hauk, Consumer Privacy Advocate at Pixel Privacy, advises:

“My first recommendation for any internet user is to visit the Have I Been Pwned website to sign up for notifications when their email address has been included in a data breach. I strongly suggest doing this for each email address they either currently use or that they had used in the past. This helps alert users when they’ve been “pwned.””

Jamie Akhtar, CEO and Co-Founder of CyberSmart, echoes this point and highlights why it’s crucial to check if you’ve been affected:

“Although much of the information exposed by the Naz.API dataset is likely to be out-of-date, it’s worth checking whether you appear in the list. Cybercriminals are guaranteed to use this data to launch further attacks, so it’s better to be safe than sorry.

To do this, perform a search at Have I Been Pwned. If your email is associated, the site should warn you that your device has been infected with malware at some point. We also recommend using multi-factor authentication (MFA) on every account you use (if you haven’t done so already). MFA gives you an extra layer of security, meaning that even if you have been compromised, it’ll make it much harder for cybercriminals to gain access to your accounts.”

Giving his advice for businesses, Nick Rago, Field CTO at Salt Security, says:

“For organisations, require MFA for your users. Don’t make it optional, especially if your applications handle sensitive data. And make sure you have the appropriate defences in place to identify and protect against malicious adversarial behaviours. Your consumer’s digital safety is also part of your responsibility.”

Erfan Shadabi, Cybersecurity Expert at comforte AG, echoes this point:

“Organisations must recognise that the responsibility to secure user data extends beyond mere compliance with regulations; it is an obligation to protect the trust that users place in them. Adopting a data-centric security strategy that prioritises protecting user data at its core is a crucial first step.”

 

ShareTweet
Previous Post

Salt Security Delivers another Technology Breakthrough with Industry’s only API Posture Governance Engine

Next Post

Keeper Security Announces Partnership with St. Anna Children’s Cancer Research Institute

Recent News

NHS cyber resilience deal signals shift toward specialist MSSPs, says Check Point

NHS cyber resilience deal signals shift toward specialist MSSPs, says Check Point

June 23, 2026
artificial-intelligence

Top Agentic SOC Vendors Defining Autonomous Security Operations

June 23, 2026
Check Point Becomes One of First Security Vendors to Embed OpenAI Frontier Models in Live Customer Defences

Check Point Becomes One of First Security Vendors to Embed OpenAI Frontier Models in Live Customer Defences

June 23, 2026
secure-software-supply-chain-feature

Black Duck Lands Leader Spot in Gartner’s Brand-New Software Supply Chain Security Magic Quadrant

June 22, 2026

The IT Security Guru offers a daily news digest of all the best breaking IT security news stories first thing in the morning! Rather than you having to trawl through all the news feeds to find out what’s cooking, you can quickly get everything you need from this site!

Our Address: 10 London Mews, London, W2 1HY

Follow Us

© 2015 - 2024 IT Security Guru - Website Managed by Dessol

  • About Us
Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us

© 2015 - 2024 IT Security Guru - Website Managed by Dessol