The LiveJournal Breach Gave Hackers 28.5 Million Plaintext Passwords
HEROIC analysts identified 28,512,956 exposed accounts tied to LiveJournal, a breach originally dated December 2014 that later surfaced publicly around 2019. The exposed data includes email addresses, usernames, and passwords stored in plaintext, making this one of the largest and most exposed breaches in HEROIC's database.
Why 28.5 Million Plaintext Passwords Is a Worst Case Breach
Plaintext passwords mean there was no hashing or encryption standing between the LiveJournal database and an attacker's ability to read every password directly. At this scale, more than 28.5 million accounts, this isn't a small leak affecting a niche audience. It's a breach large enough that the odds of your own email address being included are meaningfully high if you ever had a LiveJournal account.
What Was Exposed in the LiveJournal Breach
- Email addresses
- Usernames
- Plaintext passwords
Why This Matters for LiveJournal Users
Because these passwords required no cracking, attackers could immediately use them in credential stuffing attacks, feeding the leaked email and password pairs into automated tools that test them against banking sites, email providers, and social media platforms. At a scale of nearly 30 million accounts, this breach has likely contributed to countless account takeovers wherever a LiveJournal password was reused.
How This Database Breach Exposed Plaintext Passwords
This incident is classified as a database breach, meaning attackers gained direct access to LiveJournal's user database rather than collecting data through malware. What sets this breach apart is that passwords were stored in plaintext rather than hashed, so once attackers accessed the database, they had immediate, ready-to-use credentials for every one of the 28,512,956 accounts, with no additional cracking step required.
Check If You Are Affected by the LiveJournal Breach
You don't need to guess whether your information was part of the LiveJournal breach or any other leak. HEROIC's free breach scanner checks your email address against a database of more than 400 billion leaked records and shows you exactly what was exposed. If you find a match, change the password on any account still using it and enable multi-factor authentication where you can.
Breach Breakdown
28,512,956 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds