[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f397khd8307txd":3},{"success":4,"breach":5},true,{"_id":6,"name":7,"title":8,"slug":9,"domain":10,"breachDate":11,"addedDate":12,"modifiedDate":12,"contentUpdatedAt":13,"source":14,"sourceUrl":15,"sourceUrls":16,"pwnCount":19,"affectedCount":19,"affectedCountStatus":20,"affectedCountLowerBound":21,"affectedCountUnit":22,"hasEnglishDescription":4,"severity":23,"dataClasses":24,"description":27,"seoTitle":10,"seoTitleEn":28,"seoDescription":10,"seoDescriptionEn":29,"logoUrl":30,"isVerified":4,"isSensitive":31,"isSpamList":4,"isMalware":31,"company":32},"68e3266eda11adda488252ee","Onliner Spambot","Onliner Spambot Spam Data List","onliner-spambot","","2017-08-28T00:00:00.000Z","2017-08-29T19:25:56.000Z","2026-07-18T23:55:30.035Z","Verified breach record","https:\u002F\u002Fwww.troyhunt.com\u002Finside-the-massive-711-million-record-onliner-spambot-dump\u002F",[15,17,18],"https:\u002F\u002Fwww.twingate.com\u002Fblog\u002Ftips\u002Fonliner-spambot-data-breach","https:\u002F\u002Fzvelo.com\u002Fspambot-leak-711-million-email-addresses-ensnared\u002F",711477622,"known",null,"email_identifiers","Critical",[25,26],"Email addresses","Passwords","\u003Cp>The \u003Cstrong>Onliner Spambot data breach\u003C\u002Fstrong> dated August 28, 2017, is associated with the exposure of a large-scale credential dataset used for spam distribution and account testing attacks. In the incident, 711,477,622 unique email addresses were verified, and a significant portion of these addresses were accompanied by password information. It should not be read as a breach of a single company's customer accounts; it is a verified data leak to be considered in the context of a non-domain, malicious spam operation. This distinction is important to show the user the correct security steps.\u003C\u002Fp>\n\u003Ch2>Leaking Data Types and Risks\u003C\u002Fh2>\n\u003Cp>\u003Cstrong>Onliner Spambot\u003C\u002Fstrong> incident confirmed that the data classes are email addresses and passwords. Email addresses can be used for spam, phishing, and target selection. When combined with password information, the risk becomes more serious; because attackers can attempt account takeover by trying the same email and password pair on different services. Such attacks carry a high risk, especially for people who use the same password across different accounts. Email accounts, social media, shopping, gaming, cloud storage, and work tools can be affected by this risk.\u003C\u002Fp>\n\u003Cp>In this data set, fields such as phone number, physical address, payment card, official ID number, or private message are not included as verified data classes. The central risk is the email and password match. Whether the password is in plain text or in a different format may not be visible for each user individually; however, the presence of a password field necessitates the rapid change of reused passwords. If old passwords are still being used on other accounts, the security risk persists even years after the incident.\u003C\u002Fp>\n\u003Cp>The spam bot context also poses a different kind of threat. Compromised or guessed email accounts can be used to send malicious messages. This situation can affect not only the account owner but also friends, customers, or colleagues who receive emails from that person. A fake invoice, shipping notification, meeting invitation, or security alert from a familiar address may appear more convincing. For this reason, the Onliner Spambot result highlights not only the risk of password reuse but also the potential misuse of the email account.\u003C\u002Fp>\n\u003Ch2>Verified Scope and Boundaries\u003C\u002Fh2>\n\u003Cp>The verified scope is that the Onliner Spambot dataset dated August 28, 2017 affects 711,477,622 unique accounts, is added to the verified data breach records on August 29, 2017, and the leaked fields are email addresses and passwords. The record is of a spam list nature and should not be considered as the customer database of a specific organization. Therefore, it is correct that the domain and website fields remain empty; the incident should not be attributed to a single brand or user account system.\u003C\u002Fp>\n\u003Cp>In this incident, users are not expected to register on a website with the relevant name. The email address may have appeared on lists from different sources and later been used or tested in a spam operation. Therefore, the match seen on the results screen does not indicate that the user has registered for a service called Onliner Spambot. A more accurate interpretation is that the address, and any password information if available, was found in data files involved in a large-scale malicious mail operation.\u003C\u002Fp>\n\u003Cp>Unverified data fields should not be added to the list. For this event, fields such as payment card, bank account, health information, physical address, or phone number should not be presented to the user as if they have been exposed since they have not been verified. In contrast, email and password fields require strong action regarding account security. Keeping the scope narrow but accurate prevents both generating false fear and overlooking the actual risk of password reuse.\u003C\u002Fp>\n\u003Ch2>User Groups at Risk\u003C\u002Fh2>\n\u003Cp>People who use the same password across multiple services are in the highest risk group. If a password has been used on an old forum, shopping site, or game account and then repeated on email, social media, or work accounts, attackers may try this information on other systems. If the user does not remember where the password was used, they should start with critical accounts and move to a unique password scheme. The email account should be protected first because it is central to password reset processes.\u003C\u002Fp>\n\u003Cp>The second risk group consists of employees whose corporate email addresses appear in the dataset. If an employee's address and password are on such a list, it does not prove direct access to company systems; however, it provides credentials for attackers to try. Multi-factor authentication and failed login tracking are especially important for accounts in management, finance, human resources, support, and technical teams. Organizations should address a large number of matches with the same domain through bulk password resets and awareness notifications.\u003C\u002Fp>\n\u003Cp>The third risk group consists of people who continue to use old email addresses or old password patterns. Even if the data breach is old, the user may continue the same password pattern on current accounts. Attackers may try to find valid accounts by comparing old lists with new data sets. Therefore, it is not correct to look only at 2017 and assume the risk is in the past; the real question is whether the same information is still being used on other accounts today.\u003C\u002Fp>\n\u003Ch2>Urgent Measures to Be Taken\u003C\u002Fh2>\n\u003Cp>Users whose accounts appear as a result of the Onliner Spambot should first change all accounts where they use the same or similar password. Priority should be given to email accounts, banking, payment services, social media, work tools, cloud storage, and frequently used shopping accounts. New passwords should be unique, long, and able to be stored with a password manager. Reusing an old password with minor changes does not provide sufficient security.\u003C\u002Fp>\n\u003Cp>The second step is to enable multi-factor authentication. Application-based authentication or a hardware security key helps protect the account even if the password is compromised. Open sessions, unrecognized devices, recovery emails, and recent login activity should be checked in account settings. Suspicious sessions should be closed, recovery information should be updated, and email forwarding rules should be reviewed.\u003C\u002Fp>\n\u003Cp>The third step is to be careful against spam and fraudulent messages. Since addresses associated with this incident can be used in malicious mail operations, users should be cautious about unexpected attachments, invoice links, shipping notifications, and account security alerts. Instead of clicking on links, the address of the relevant service should be typed into the browser manually, and unexpected verification codes should not be shared with anyone. Corporate users should report suspicious messages to the security team.\u003C\u002Fp>\n\u003Ch2>Long-Term Security Strategies\u003C\u002Fh2>\n\u003Cp>Using a unique password for each account is the basic rule for long-term protection. A password manager makes it easy to manage strong and random passwords for hundreds of different accounts. Users should abandon old and repeated passwords, keep security notifications enabled for important accounts, and make regular leak checks a habit. This way, information appearing on a spam bot list can be rendered ineffective without spreading to other accounts.\u003C\u002Fp>\n\u003Cp>From the perspective of institutions, a permanent strategy is to regularly monitor the visibility of employee emails in external data sets and to prioritize high-privilege accounts. Failed login attempts, unusual locations, new device sessions, and email forwarding changes should be monitored. When training that reduces password reuse, mandatory multi-factor authentication, risk-based login controls, and security key support are addressed together, the likelihood of account takeover decreases.\u003C\u002Fp>\n\u003Cp>This incident also reminds us of the central role of the email account for digital identity. If an email account is compromised, an attacker can initiate the password reset process on many services. Therefore, a unique password for the email account, strong two-factor authentication, up-to-date recovery information, and regular session checks are essential. Users should close old accounts, avoid using addresses they no longer use to access critical services, and take security alerts seriously.\u003C\u002Fp>\n\u003Ch2>Record Control and User Action\u003C\u002Fh2>\n\u003Cp>If your email address appears in the \u003Cstrong>Onliner Spambot data breach\u003C\u002Fstrong>, do not interpret this as meaning that you signed up for a specific website. A more accurate assessment is that your email address, and in some cases password information, was found in datasets used in malicious spam operations. The priority is to understand whether the same password is used on other accounts and to quickly remove repeated passwords.\u003C\u002Fp>\n\u003Cp>If the check result provides a match, password changes should be implemented on critical accounts starting from your email account, as well as multi-factor authentication, active session review, and suspicious message monitoring. Domain-based monitoring for corporate addresses makes it easier to prioritize high-risk employee accounts. Regular record checks help to detect early the risk arising from old data sets being reused in new attacks.\u003C\u002Fp>","Onliner Spambot Spam Data List (711.5 Million Email Identifiers)","Onliner Spambot Spam Data List. 711.5 Million email identifiers were reported. Reported data: Email addresses, Passwords. Review the scope, risks, and…","\u002Fuploads\u002Flogo\u002Fonliner_spambot.webp",false,{"name":7,"sector":33,"country":10,"website":10,"websiteArchiveUrl":10,"websiteStatus":10,"websiteCheckedAt":21},"Malware \u002F Spam Bot"]