Back to the archive

The encyclopedia · Software & IT · Operational decision · 2016

LinkedIn's 2012 breach exposed 6.5M passwords — the full 117M came out 4 years later

In 2012, hackers stole 6.5M LinkedIn passwords. LinkedIn disclosed a partial breach. In 2016, the full 117M records appeared for sale. The delay cost trust.

LinkedIn · Microsoft · 2016-05

What happened

In June 2012, LinkedIn disclosed that hackers had stolen approximately 6.5 million user passwords. The company reset affected passwords and urged users to change their credentials. The breach was treated as a limited incident.

In May 2016, a hacker offered 117 million LinkedIn email-password combinations for sale on a dark web marketplace. The data was from the same 2012 breach, but the full scope had not been disclosed. LinkedIn confirmed that the data was authentic and that the 2012 breach had been far larger than initially reported.

The four-year gap between the breach and the full disclosure was widely criticized. LinkedIn (acquired by Microsoft in 2016) was accused of downplaying the breach to protect its reputation during its IPO period. The case illustrated how the incentive to minimize a breach's perceived scope can delay disclosure and compound the damage to user trust.

Why it happened

  • LinkedIn disclosed a partial breach (6.5M passwords) in 2012; the full breach was 117M records.
  • The full scope was not disclosed until 2016, when the data appeared for sale.
  • LinkedIn was accused of downplaying the breach during its IPO period.
  • The four-year delay compounded the damage to user trust.
What it cost117M records; 4-year disclosure delay; trust damagedcostly

The lesson

The incentive to minimize a breach's scope delays disclosure and compounds the damage. LinkedIn said 6.5M; it was 117M. The full truth always surfaces; the delay is the cost.

Aftermath

LinkedIn reset all passwords and implemented stronger security. The case influenced breach disclosure practices and contributed to the EU's GDPR requirements for timely breach notification.

Sources

spotted an error? The club wants to know.

Comments · 0

    Sign in to join the comments.

    More like this

    Somewhere, someone solved the problem this company failed at. 2nd Opinion →