The hackers collected data on a massive scale, 'so it affects absolutely everybody,' security firm says Criminals in Russia have amassed a huge database of 1.2 billion stolen user names and passwords and half a billion email addresses, a U.S.-based Internet security company said Wednesday.The data, believed to be the single biggest horde of stolen Internet identity information ever collected, was garnered from attacks that reached into every corner of the Web and hit around 420,000 sites, said Hold Security.“Before, we were amazed when 10,000 passwords [went] missing. Now we’re in the age of mass production of stolen information,” Alex Holden, the company’s founder and chief information security officer, told IDG News Service in a telephone interview.Hold Security didn’t identify the websites that were breached, citing confidentiality agreements with clients, but it said they include household names as well as small websites. The New York Times, which first reported the story, said it hired an independent security expert who verified that the stolen data is authentic.The sheer scale of the database appears to dwarf similar discoveries in the past. By comparison, the recent theft from Target affected 40 million credit and debit card numbers and 70 million personal records. That was one of the largest breaches of all time, but the activities of the Russian gang take identity theft to a new level.“These guys did nothing new or innovative,” said Holden. “They just did it better and on a mass level so it affects absolutely everybody.”Martyn Williams covers mobile telecoms, Silicon Valley and general technology breaking news for The IDG News Service. Follow Martyn on Twitter at @martyn_williams. Martyn’s e-mail address is martyn_williams@idg.com Related content news Immersive Labs adds custom 'workforce exercising' for each organizational role With the new workforce exercising capability, CISOs will be able to see each role’s cybersecurity readiness, risk areas, and exercise progress. By Shweta Sharma Sep 27, 2023 3 mins Security Software Security news Sysdig unveils cloud attack graph based on real-time threat data Sysdig also announced a new cloud inventory and agentless scanning capabilities to tackle cloud security risks. By Michael Hill Sep 27, 2023 3 mins Threat and Vulnerability Management Cloud Security Storage Security feature What’s a cyber incident response retainer and why do you need one? Whether you need to hire a team to respond to any and all cyberattacks or just some hired guns to boost your capabilities, incident response retainers can ensure you’re covered. By Linda Rosencrance Sep 27, 2023 8 mins Cyberattacks Incident Response Security Practices brandpost How an integrated platform approach improves OT security By Richard Springer Sep 26, 2023 5 mins Security Podcasts Videos Resources Events SUBSCRIBE TO OUR NEWSLETTER From our editors straight to your inbox Get started by entering your email address below. Please enter a valid email address Subscribe