Now Might Be A Good Time To Change Your Gmail, Hotmail Or Yahoo Password

Hold Security, a company specializing in information security assessment, risk management and incident response, announced that it has discovered a cache of over 1.17 billion stolen online credentials from a Russian hacker that collected the data from a variety of breached sources, including Gmail, Yahoo and Microsoft.

Latest Videos FromTom's Hardware
Contributor

Derek Forrest was a contributing freelance writer for Tom's Hardware. He covered hardware news and reviews, focusing on gaming desktops and laptops.

  • DookieDraws
    Wow! I just did this less than a minute ago before coming here! CREEEEEPY! :P

    I changed my password to 0987654321ABCDE, so nobody use this, okay? :)
    Reply
  • problematiq
    While it's good to keep your password in rotation, it's been shown that this was a media hyped "Hack" most if not all the data was recycled from older hacks and or public data with some randomly generated emails salted in.
    Reply
  • hasten
    Wow! I just did this less than a minute ago before coming here! CREEEEEPY! :P

    I changed my password to 0987654321ABCDE, so nobody use this, okay? :)
    Dude. Now I have to change mine again... although I did it 2 hours ago, so it's only fair that you change yours...
    Reply
  • DookieDraws
    17922816 said:
    Wow! I just did this less than a minute ago before coming here! CREEEEEPY! :P

    I changed my password to 0987654321ABCDE, so nobody use this, okay? :)
    Dude. Now I have to change mine again... although I did it 2 hours ago, so it's only fair that you change yours...

    My bad. Okay, I went ahead and changed mine to 0987654321ABCDEF, so you can keep yours as is. I just added an F to mine so I wouldn't have to remember anything else. Now if I can just remember to add the F on the end.:pt1cable:
    Reply
  • pierrerock
    I have this thing : google send me a text to confirm my identity. Am i still good or do i need to change my password ?
    Reply
  • ledhead11
    WOW! I tried P@ssw0rd, 123456#Abcd, & D3f@ult and I'm still locked out. . . .maybe I got a $1 laying around somewhere. . .
    Reply
  • Caanis Lupus
    17922816 said:
    Wow! I just did this less than a minute ago before coming here! CREEEEEPY! :P

    I changed my password to 0987654321ABCDE, so nobody use this, okay? :)
    Dude. Now I have to change mine again... although I did it 2 hours ago, so it's only fair that you change yours...

    My bad. Okay, I went ahead and changed mine to 0987654321ABCDEF, so you can keep yours as is. I just added an F to mine so I wouldn't have to remember anything else. Now if I can just remember to add the F on the end.:pt1cable:

    https://www.youtube.com/watch?v=B-NhD15ocwA

    @pierrerock If you have that turned on you should be good to go since they would need the code from your text message, also will let you know IF someone is trying to connect to your account.
    Reply
  • gggplaya
    Every company should have the ability to do 2-step verification. Now i simply don't worry about it. Even if they steal the password, they still can't get in.
    Reply
  • hdmark
    but even with 2 step, i thought a big part of password breaches like this is that if you use any common passwords , they now have one of your passwords. not that its smart or that i do this (anymore...) but lets say my gmail pass was the same as my TD bank, they now have my email and pass.
    i guess this is a benefit of using things like password managers that randomly generate new passwords?
    Reply
  • gggplaya
    17924818 said:
    but even with 2 step, i thought a big part of password breaches like this is that if you use any common passwords , they now have one of your passwords. not that its smart or that i do this (anymore...) but lets say my gmail pass was the same as my TD bank, they now have my email and pass.
    i guess this is a benefit of using things like password managers that randomly generate new passwords?

    My Gmail, amazon and paypal are 2 step. None have been hacked since implementing 2 step. Someone tried to hack my paypal, but it kept sending me text messages with authorization codes, at like 3am. I literally got over 100 messages before i woke up and quickly changed my password. 2-step worked like it's supposed to. My godaddy was hacked because i didn't have 2-step, but after recovering my account(long process), i enabled 2 step on it and hasn't been hacked since.

    Anything else are just forums and random websites which don't handle my credit card info. Hacking them really doesn't gain them much.
    Reply