Huntress finds 150k+ compromised accounts in the wild — and they're not who you think
Huntress dug into a batch of breached credentials and found 150,000 unique accounts that had been used in credential stuffing attacks. The twist: most of the logins didn't belong to corporate employees. They belonged to personal email accounts — Gmail, Yahoo, Outlook — the ones people use to pay rent, sign up for their kid's school portal, check their bank balance.
The accounts were compromised through the usual chain: a data breach somewhere, the email and password scraped, then sold, then tried against every site they can guess. It's the digital version of someone picking your pocket at a bodega and using the same wallet elsewhere. What Huntress flagged is the scale — 150,000 is enough to hit a significant chunk of any neighborhood. And the targets aren't Fortune 500 execs. They're primos trying to log into their Chase account, a teacher checking grades, a nurse looking up a prescription.
Why this matters for us: If you're still using the same password on your personal email that you use for your bank or your work, la migra is already past the door — change it now, and turn on 2FA before the next breach drops.
“The accounts aren't Fortune 500 execs. They're the ones you use to pay rent.”