Breach date: 2016-12-16. Added to this index: 2017-05-04. Accounts affected: about 458M. Domain: not listed.
In December 2016, a huge list of email address and password pairs appeared in a "combo list" referred to as "Anti Public". The list contained 458 million unique email addresses, many with multiple different passwords hacked from various online systems. The list was broadly circulated and used for "credential stuffing", that is attackers employ it in an attempt to identify other online systems where the account owner had reused their password. For detailed background on this incident, read Password reuse, credential stuffing and another billion records in Have I Been Pwned.
Breach data sourced from Have I Been Pwned, used under CC BY 4.0. Additional breach metadata provided by XposedOrNot. DataExposed is an independent service and is not affiliated with or endorsed by either.
The Anti Public Combo List breach exposed Email addresses, Passwords. About 458M accounts were affected.
Run the free email breach check with the address you used on that service. It will tell you whether your address appears in this dataset.
Change the password on that account and everywhere you reused it, then turn on two-factor authentication. Passwords from this breach are traded and tried automatically against other sites.