During 2025, the cybersecurity firm Synthient aggregated approximately 2 billion unique email addresses and 1.3 billion unique passwords from credential-stuffing lists found across various malicious internet sources. This information was compiled and disclosed by Synthient, a threat-intelligence firm, and subsequently made searchable by Have I Been Pwned.
The compromised data types are limited to email addresses and passwords. While 2 billion affected accounts have been reported, this refers to the scope of the aggregated data and not necessarily individuals directly breached from Synthient's own systems. There is no public confirmation of specific U.S. states affected, nor any indication of financial, medical, or SSN data being involved in this aggregation. Synthient itself appears in this context as a researcher and not a breached entity.
It is important to note that details regarding security incidents can evolve, and further information may be disclosed over time.