The encyclopedia · Software & IT · Operational decision · 2016
LinkedIn's 2012 breach exposed 6.5M passwords — the full 117M came out 4 years later
In 2012, hackers stole 6.5M LinkedIn passwords. LinkedIn disclosed a partial breach. In 2016, the full 117M records appeared for sale. The delay cost trust.
LinkedIn · Microsoft · 2016-05
What happened
In June 2012, LinkedIn disclosed that hackers had stolen approximately 6.5 million user passwords. The company reset affected passwords and urged users to change their credentials. The breach was treated as a limited incident.
In May 2016, a hacker offered 117 million LinkedIn email-password combinations for sale on a dark web marketplace. The data was from the same 2012 breach, but the full scope had not been disclosed. LinkedIn confirmed that the data was authentic and that the 2012 breach had been far larger than initially reported.
The four-year gap between the breach and the full disclosure was widely criticized. LinkedIn (acquired by Microsoft in 2016) was accused of downplaying the breach to protect its reputation during its IPO period. The case illustrated how the incentive to minimize a breach's perceived scope can delay disclosure and compound the damage to user trust.
Why it happened
- LinkedIn disclosed a partial breach (6.5M passwords) in 2012; the full breach was 117M records.
- The full scope was not disclosed until 2016, when the data appeared for sale.
- LinkedIn was accused of downplaying the breach during its IPO period.
- The four-year delay compounded the damage to user trust.
The lesson
The incentive to minimize a breach's scope delays disclosure and compounds the damage. LinkedIn said 6.5M; it was 117M. The full truth always surfaces; the delay is the cost.
Aftermath
LinkedIn reset all passwords and implemented stronger security. The case influenced breach disclosure practices and contributed to the EU's GDPR requirements for timely breach notification.
Sources
spotted an error? The club wants to know.
More like this
Okta's support engineer was screen-shared into — and 366 customers were breached
LastPass was hacked twice in 2022 — the second breach exposed password vaults
Hackers exploited zero-days in Microsoft Exchange — and 250,000 servers were compromised
Somewhere, someone solved the problem this company failed at. 2nd Opinion →

Comments · 0
Sign in to join the comments.