On September 20, 2023, 70.8 million email addresses and roughly 100 million plaintext passwords tied to the Naz.API corpus appeared in a public hacking forum. The collection, exceeding 100 GB, consists of stealer logs and credential-stuffing lists that pair addresses with passwords and the specific services where those credentials were used. Anyone whose email is among the 71 million unique addresses now faces immediate risk of account takeover wherever the same password was reused.
Named in this incident?
You can’t unleak data. You can take away what it’s worth.
A leaked record is where it starts, not where it ends. What turns it into your front door is the look-up sites publishing your address beside your name — and those are what an AI reads when somebody asks about you. The free scan shows you both. We write to 582 companies.
See what is exposed about you — free scan →Not ready yet? Run a free breach check on this email
We’ll check it against 13.1B+ leaked records right now — no account needed. Continuous monitoring & alerts are part of Protection.
Reported Details from the Disclosure
The primary listing on Have I Been Pwned states that the Naz.API dataset combines two main types of material: logs from information-stealer malware and large credential-stuffing dictionaries. It contains email-password pairs that include the target service for each pair, plus standalone credential sets whose original sources are not identified. The disclosure does not specify which exact services were most heavily represented or name any particular malware family responsible for the initial theft. What is certain is the scale: more than 70.8 million affected users and a total volume that makes selective targeting straightforward for criminals.
Why This Matters for You and Your Family
If your email address is in the Naz.API dump, every account that shares those passwords is exposed. Criminals do not need sophisticated tools; they simply test the leaked pairs against banks, email providers, social media, shopping sites, and government portals. When a password has been reused across personal, work, and family accounts, one breach quickly becomes many. Children’s accounts, often secured with the same family passwords or slight variations, are especially vulnerable because parents rarely monitor them as closely as their own. The exposure is not theoretical. Credential pairs like these are sold and traded within hours of appearing in forums, turning yesterday’s unnoticed breach into today’s active compromise.
The Doxxing and Identity-Chain Risk
Plaintext passwords paired with emails create direct pathways to doxxing. Once an attacker logs into one service, they can harvest additional personal details—phone numbers, addresses, dates of birth, and linked accounts—then pivot to others. These identity chains grow rapidly: a gaming account leads to a parent’s email, which leads to a family photo repository, which reveals children’s names and schools. The Naz.API material, because it already maps emails to specific services, accelerates this chaining process. What begins as a credential leak can end with full identity exposure, harassment, or targeted scams against every member of a household.