Just got this from @haveibeenpwned and, honestly I hate it.
- service I never used
- it’s a threat intel company
- 2 billion emails (and some pw)
Is it recent data? If I auto generate a list of every possible email ever (and maybe some bogus passwords) do we notify everyone?
troyhunt.com/2-billion-email… please read this and reevaluate your statement
So I’m going to take this breach, and generate a list of every possible email address ever. Then I’ll include this breach, and add randomly generated passwords or copy others into emails that don’t have a password in this breach. This would then cause a breach notification for every single email address ever created. Reasonable?
here was the research piece which we published on the matter. We aren’t a threat intel company and this was shared as a contribution towards the cybersecurity community.
synthient.com/blog/the-steal…
Nov 8, 2025 · 9:10 PM UTC



