EARF
United States Flag
United StatesNorth America
Japan Flag
JapanAsia
Italy Flag
ItalyEurope
Netherlands Flag
NetherlandsEurope
United Kingdom Flag
United KingdomEurope
EARFSTAGE
EARFSTAGEFestivals and live sets
METAR | EARF
EARFWeatherLive weather stations
EARFWiki
EARFWikiCountries and public records
EARFguessGuess where on Earth
/data-breach/linkedin-breach-2012
332/430

File EL-0099HighResolvedData Breach / Credential Theft

LinkedIn Password Hash Breach

Also filed as LinkedIn Data Leak · LinkedIn Credential Theft

This incident involved the unauthorized exfiltration of a massive dataset containing password hashes and associated user information from LinkedIn. The breach exposed credentials belonging to approximately 117 million accounts. The leaked data was sold on the dark web, representing a significant early example of large-scale credential theft from a major social professional platform.

  • #linkedin
  • #password-hash
  • #data-breach
  • #credential-theft
  • #2012
Notoriety7/10
Event
5 Jun 2012
Disclosed
5 Jun 2012
Target
LinkedIn Corporation
Actor
Yevgeniy Nikulin
Scale
117.0M people
Status
Resolved

01Summary

The breach occurred in 2012, targeting LinkedIn's user database. The attacker, identified as Yevgeniy Nikulin, managed to steal a substantial volume of user credentials, specifically the password hashes. These hashes, while not the plain-text passwords, were highly valuable to criminal groups for subsequent cracking attempts. The data was subsequently marketed and sold on underground forums and dark web marketplaces. The scale of the leak—affecting over 117 million users—highlighted the growing vulnerability of large online platforms to sophisticated data theft, even before modern multi-factor authentication became standard practice.

02Background

In the early 2010s, professional networking sites like LinkedIn were rapidly expanding their user base, making them attractive targets for cybercriminals. Security practices, while improving, were often insufficient to protect the sheer volume of sensitive user data being collected and stored. This breach demonstrated the immense value of centralized user credentials.

03Key revelations

  1. 01The sheer scale of the compromised dataset, affecting over 117 million users.
  2. 02The vulnerability of professional networking sites to large-scale credential theft.
  3. 03The market value of hashed credentials on underground forums.

04Technical analysis

The attack vector was likely an exploitation of an internal vulnerability or compromised credentials allowing access to the database containing the hashed passwords. The data exfiltrated consisted primarily of password hashes, which, depending on the hashing algorithm and salt usage, could be subjected to offline brute-force or dictionary attacks. The lack of immediate, robust hashing standards (like modern Argon2 or bcrypt) made the data particularly valuable.

Attack vector
Internal vulnerability or compromised database access
Attack method
Data Exfiltration
Initial access
Exploitation of internal system weakness
Exfiltration
Database dump/bulk transfer
Malware type
Stealer

Vulnerabilities exploited

  • Database access vulnerability

MITRE ATT&CK techniques

  • T1021.001
  • T1046

05Threat actor

Yevgeniy Nikulin is documented as an individual hacker who targeted corporate databases for financial gain. His profile represents early, opportunistic cybercrime focused on selling bulk data on underground markets, predating the highly organized APT groups of later years.

Aliases

  • Nikulin

MITRE groups

  • T1003

Known members

  • Yevgeniy Nikulin

Attribution sources

  • Media Reports
  • Security Researchers

06Victims and impact

Countries affected

  • United States

07Data exposed

Data types

  • Password Hashes
  • User IDs
  • Email Addresses

Notable documents

  • Password Hash Dump

08Financial damage

Damage estimate is based on the potential for identity theft and subsequent account takeover.

09Timeline

  1. 2012-06-05Breach discovered and reported publicly

10Key figures

  • Yevgeniy NikulinAttacker/BreacherRussianUnknown/Unaccounted for

11Reaction and fallout

Public reaction

The breach triggered widespread alarm regarding the security practices of major online platforms. It spurred public and regulatory discussion about the necessity of stronger password hashing and mandatory multi-factor authentication.

Political impact

It contributed to a growing global regulatory push, particularly in Europe, toward stricter data protection laws (precursor to GDPR) and mandatory breach reporting.

12Legal

LinkedIn faced increased scrutiny from regulators, leading to internal security overhauls and changes in data handling protocols.

Civil lawsuits

  • Class-action lawsuits related to data security failures (general trend)

13Aftermath

Policy changes

  • Increased industry adoption of modern, salted, and adaptive hashing algorithms (e.g., bcrypt, Argon2)
  • Enhanced focus on mandatory Multi-Factor Authentication (MFA) implementation

Regulatory changes

  • Increased global regulatory focus on data residency and breach notification timelines

Security improvements

  • Mandatory implementation of MFA for high-value accounts
  • Adoption of zero-trust architecture principles in corporate networks

14Significance and legacy

Significance

This incident is a landmark case in the history of data breaches, demonstrating the massive commercial value of centralized, unencrypted, or weakly hashed user credentials. It served as a critical early warning that professional networking sites were not immune to sophisticated, large-scale data theft, forcing the industry to rapidly improve its cryptographic standards and security architecture.

Legacy

The breach accelerated the industry shift away from simple hashing methods (like MD5 or SHA-1) toward computationally intensive, salted, and adaptive hashing functions. It also contributed to the normalization of the concept of 'data breach' as a major corporate risk, leading to the establishment of dedicated Chief Information Security Officer (CISO) roles.

15Disclosure and media

Authentication
Public reporting and data analysis

Media partners

  • The Guardian
  • Reuters

Publishing organisations

  • Security Researchers

16Related files

Went on to inspire

  • credential-stuffing-attacks

17Field notes

  1. 01The breach occurred before the widespread adoption of MFA, making the stolen hashes particularly potent for attackers.
  2. 02The incident highlighted that even major corporations were susceptible to internal database vulnerabilities.

18Resolution

LinkedIn publicly acknowledged the breach and implemented significant security upgrades, including the mandatory adoption of stronger hashing algorithms and enhanced internal access controls.

19Sources

References

  1. [1]The Guardian reporting on the 2012 breach
  2. [2]Cybersecurity industry reports from 2012-2013
Fact sheetEL-0099

Dates

Event
5 Jun 2012
Started
5 Jun 2012
Ended
5 Jun 2012
Duration
1 days
Discovered
5 Jun 2012
Disclosed
5 Jun 2012
Ongoing
No

Target

Organisation
LinkedIn Corporation
Type
Technology Company
Sector
Professional Networking
Country
United States

Actor

Name
Yevgeniy Nikulin
Type
Individual Hacker
Nationality
Russian
Motivation
Financial gain and notoriety through data sale
Attribution
Medium
Status
Active
Arrested
No
Convicted
No

Data

People
117,000,000
Records
117,000,000
Volume
Unknown (estimated to contain hashes for 117 million accounts)
Sensitivity
Confidential
Published
No
Sold (dark web)
Yes

EARFLeaks documents publicly known security incidents. It does not host, store or distribute leaked data.

© 2026 EARF. All rights reserved.