allmergeraccounts
We've been tracking a resurgence of older database breaches surfacing in underground communities, often repackaged and sold as "new" leaks. What caught our attention about this particular dataset wasn't the size—just under 300,000 records—but the age and source. The breach stems from allmergeraccounts, dating back to December 31, 2015. The data has been circulating quietly for years, but its reappearance signals potential for renewed password reuse attacks and credential stuffing attempts. The fact that it's being peddled again highlights the long tail of risk associated with even older breaches.
The Allmergeraccounts Leak: A Resurfaced Threat From 2015
The allmergeraccounts breach, which occurred on December 31, 2015, has resurfaced in several online forums and Telegram channels. We discovered its renewed circulation on Breach Forums on October 26, 2024. While the breach itself is not new, its reappearance suggests threat actors are actively seeking value from older datasets, likely targeting individuals who may have reused passwords across multiple platforms. The leak caught our attention due to the presence of IP addresses alongside email addresses and password hashes, potentially allowing for more targeted attacks based on geographical location or past online behavior.
- Total records exposed: 290,850
- Types of data included: Email Address, IP Address, Password Hash
- Sensitive content types: None specifically, but email addresses and password hashes can be used to access other sensitive accounts.
- Source structure: Database
- Leak location(s): Breach Forums, various Telegram channels known for trading compromised data.
- Date of first appearance: December 31, 2015 (initial breach); resurfaced on October 26, 2024.
External Context & Supporting Evidence
While specific news coverage of the original allmergeraccounts breach from 2015 is limited, similar breaches from that era have been widely reported. Data breaches involving password hashes from older platforms often reappear in "combo lists" used for credential stuffing attacks, as highlighted in numerous reports by cybersecurity firms like Recorded Future and Flashpoint. These reports detail how attackers compile massive databases of leaked credentials from various sources and use them to automatically attempt logins on other websites and services. One Telegram post claimed the files were being used to target accounts on e-commerce platforms, indicating a potential motive behind the renewed interest in this older dataset.
Breach Breakdown
290,850 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds