Breach date: 2018-09-11. Added to this index: 2018-09-13. Accounts affected: about 42M. Domain: not listed.
In September 2018, a collection of almost 42 million email address and plain text password pairs was uploaded to the anonymous file sharing service kayo.moe. The operator of the service contacted HIBP to report the data which, upon further investigation, turned out to be a large credential stuffing list. For more information, read about The 42M Record kayo.moe Credential Stuffing Data.
Breach data sourced from Have I Been Pwned, used under CC BY 4.0. Additional breach metadata provided by XposedOrNot. DataExposed is an independent service and is not affiliated with or endorsed by either.
The Kayo.moe Credential Stuffing List breach exposed Email addresses, Passwords. About 42M accounts were affected.
Run the free email breach check with the address you used on that service. It will tell you whether your address appears in this dataset.
Change the password on that account and everywhere you reused it, then turn on two-factor authentication. Passwords from this breach are traded and tried automatically against other sites.