Login histories leaked: what it means and what to do

Risk level: medium. Can you change it: no. Found in 1 breaches in this directory.

What this data is

Records of each sign-in to an account: date and time, IP address, approximate location, device and browser, and sometimes whether the attempt succeeded.

The risk on its own

A login history maps your online routine: when you are active, which devices you use and roughly where you connect from, including home, work and travel. It cannot log in to the account. It can show patterns such as when you are usually asleep or away.

The risk combined with other data

With your email and the account, an attacker learns your usual devices, locations and times, which helps them imitate you and slip past fraud checks that look for unusual sign-ins. It also shows which accounts you use actively, so they know where to aim. Travel patterns can reveal when your home is empty.

How criminals use it

  • An attacker signs in to your stolen account from a device type and city that match your normal pattern, so no security alert fires.
  • Your sign-in times show when you are usually asleep, which is when the attacker makes account changes.
  • Login locations reveal your workplace, home suburb and regular trips.

What to do now

  1. Review recent sign-ins on your important accounts: Google Account, Security, Your devices; Microsoft account, Security, Sign-in activity; Facebook, Accounts Center, Password and security, Where you're logged in.
  2. Sign out of devices you do not recognise and change the password on the breached account.
  3. Turn on two-factor authentication, preferably with an authenticator app or a passkey.
  4. Switch on new sign-in alerts wherever the service offers them.

Frequently asked questions

Can someone get into my account using my login history?

No. It does not contain your password. It helps an attacker who already has a password look more like you.

How do I check where my accounts are signed in?

Most services list active sessions and recent sign-ins in their security settings, where you can also sign out of unknown devices.

Why would a company keep my login history?

For security monitoring, fraud detection and to show you recent activity. It is useful data, which is exactly why losing it matters.

Breaches that exposed this data

  • SuperVPN & GeckoVPN: 2021-02-25, 20M accounts, Device information, Device serial numbers, Email addresses, Geographic locations, IMSI numbers, Login histories

Tools that help

Related guides

Breach data sourced from Have I Been Pwned, used under CC BY 4.0. Additional breach metadata provided by XposedOrNot. DataExposed is an independent service and is not affiliated with or endorsed by either.