[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f2vld4bk0n67qe":3},{"success":4,"breach":5},true,{"_id":6,"name":7,"title":8,"slug":9,"domain":10,"breachDate":11,"addedDate":12,"modifiedDate":13,"contentUpdatedAt":13,"source":14,"sourceUrl":15,"sourceUrls":16,"pwnCount":18,"affectedCount":18,"affectedCountStatus":19,"affectedCountLowerBound":20,"affectedCountUnit":21,"hasEnglishDescription":4,"severity":22,"dataClasses":23,"description":26,"seoTitle":10,"seoTitleEn":27,"seoDescription":10,"seoDescriptionEn":28,"logoUrl":29,"isVerified":30,"isSensitive":4,"isSpamList":30,"isMalware":30,"company":31},"68e3266eda11adda48825255","KayoMoe","Kayo.moe 2018 Dataset","kayomoe-credential-stuffing-list","","2018-09-11T00:00:00.000Z","2018-09-13T09:37:49.000Z","2026-07-29T20:29:08.228Z","Unverified breach record","https:\u002F\u002Fwww.troyhunt.com\u002Fthe-42m-record-kayo-moe-credential-stuffing-data\u002F",[15,17],"https:\u002F\u002Fweb.archive.org\u002Fweb\u002F20180914083104id_\u002Fhttps:\u002F\u002Fkayo.moe\u002F",41826763,"known",null,"email_identifiers","Critical",[24,25],"Email addresses","Passwords","\u003Cp>\u003Cstrong>The Kayo.moe 2018 dataset\u003C\u002Fstrong> is not a single-company breach but a multi-source credential collection uploaded to an anonymous file-hosting service. An external catalogue record reports a September 11, 2018 date, 41,826,763 unique email addresses, and email and password classes. There is no evidence that Kayo.moe's own systems were breached.\u003C\u002Fp>\n\n\u003Ch2>How was the collection characterized?\u003C\u002Fh2>\n\u003Cp>The service operator sent the upload to the external catalogue operator for review after noticing that it appeared to contain personal data. According to the published technical account, the collection contained 755 files totalling 1.8GB. Most files resembled the username-password format used in automated account attempts, were combined from different breaches or other sources, and had obfuscated names that did not identify provenance.\u003C\u002Fp>\n\n\u003Cp>The analyst extracted almost 42 million unique email addresses. After the complete load, approximately 93% of the addresses had previously appeared in the catalogue, while more than 91% of sampled passwords had already appeared in the password corpus. These percentages are not counts of new people, new breaches, or valid credentials. Because each source chain could not be identified, the record retains an unverified flag in the external catalogue; that flag does not mean the collection was never examined.\u003C\u002Fp>\n\n\u003Ch2>Which data types are in scope?\u003C\u002Fh2>\n\u003Cp>The structured external classes are email addresses and passwords, and the external narrative describes passwords in the context of plaintext pairs. The 41,826,763 value is a unique-email measure, not a verified account count or a count of complete email-password pairs. It should not be assumed that every email had a password, that a password remains valid, or that both values belonged to the same person.\u003C\u002Fp>\n\n\u003Cp>The source analysis also mentions logs, partial card data, and files carrying specific service names; these are not added to the two structured classes and do not prove that the named services were breached. Phone numbers, physical addresses, government IDs, complete payment cards, and private-message content are not verified classes for this record.\u003C\u002Fp>\n\n\u003Ch2>Local coverage and domain status\u003C\u002Fh2>\n\u003Cp>Production has no import job associated with this record, and every local email, password, and other person-data collection contains zero links. No conclusion can therefore be drawn about local presence, password matches, source sites, or field co-occurrence in the external collection.\u003C\u002Fp>\n\n\u003Cp>kayo.moe does not resolve in the current DNS check. A September 14, 2018 archive verifies Kayo.moe as a free, public file-hosting service; it does not authenticate the data's original sources or any individual breach. People who independently know that they reused one password across services can replace any copy that remains active with a unique password and enable multifactor authentication. An email match alone is not evidence of an active account, successful account takeover, or membership in a particular service.\u003C\u002Fp>","Kayo.moe 2018 Dataset (41.8 Million Email Identifiers)","The Kayo.moe 2018 mixed list contains 41,826,763 unique emails and a password class; the sources of its 755 files could not be verified.","\u002Fuploads\u002Flogo\u002Fkayo_moe.webp",false,{"name":32,"sector":33,"country":10,"website":34,"websiteArchiveUrl":17,"websiteStatus":35,"websiteCheckedAt":36},"Kayo.moe","Credential Collection","kayo.moe","archived","2026-07-29T20:23:00.000Z"]