A staggering number of passwords were stolen in 2024 and are now available on the dark web

(Fremont County, WY) – A massive cybersecurity threat has been uncovered by researchers and tech journalists: 19 billion compromised passwords (19,030,305,929, to be precise) are now circulating on the dark web. These stolen credentials were gathered from over 200 security incidents in 2024 alone, according to a recent Forbes report.

The CyberWyoming Alliance warns that many of these passwords are weak, reused across multiple accounts, and easily cracked – 42% are short (less than 10 characters long), and 27% use only lowercase letters and digits.

94% of the compromised passwords were reused across different accounts.

This treasure trove of data gives hackers the tools to launch widespread ‘credential-stuffing attacks’, in which login information from, for example, a person’s social media account is used to attempt access to online banking, email, and other more sensitive accounts.

Advertisement - Content Continues Below

The passwords were stolen using many different hacking methods, but experts note a sharp increase in text message-based fishing attacks, known as ‘smishing’.

“Additionally, SMS phishing (smishing) attacks, particularly by Chinese hacker groups,
are rapidly growing and exploiting unsecured SMS systems, causing significant financial losses,” CyberWyoming stated in a news release this week.

There’s no way for the typical internet user to know if their passwords have been stolen (until it’s too late), but the fix is simple: change your passwords.

Security experts recommend using strong, unique passwords for each account, enabling multi-factor authentication, and staying alert for suspicious texts or login attempts

Advertisement - Content Continues Below

Like this article? Help us do more!

Free news isn't really free. So, if you valued the content you just read, consider a small "thank you" gift to help us provide more!

Support County 10

🔒 100% Secure Donation

More from County 10