Risk level: high. Can you change it: yes. Found in 1 breaches in this directory.
Secret keys stored in encrypted form, such as cryptocurrency wallet keystore files, encrypted password manager vaults, SSH or PGP private keys and backup encryption keys, each protected by a passphrase or master password.
Encryption protects the keys only as long as the passphrase holds. Once the file is stolen, attackers can try passwords offline at high speed, with no lockout and no alert to you. A long random passphrase may never fall, but a short or reused one can, and the attacker can take as long as they like.
Linked to your email and other breaches, attackers try your known passwords and their variations first, which is exactly how weak passphrases fall. If the keys control cryptocurrency, success means the funds are gone for good. If it is a password vault, every stored login is at risk, and if it is a server key, the systems you manage are exposed.
Only if your passphrase was long, random and unique. Stolen encrypted files can be attacked offline with no limit on attempts, so rotate the keys anyway.
It depends on its length, its randomness and how the file was encrypted. Short or reused passphrases can fall quickly, while long random ones are impractical to crack. Do not bet money on it.
Anything that controls money, such as crypto wallets, then your email account, then everything else in order of the damage it could do.
Breach data sourced from Have I Been Pwned, used under CC BY 4.0. Additional breach metadata provided by XposedOrNot. DataExposed is an independent service and is not affiliated with or endorsed by either.