RockYou2021 made headlines last week for being the largest computer breach in history — but two leading security firms told Bank Automation News that it’s more hype than reality.

The release was touted as the “largest password compilation of all time,” with a purported 8.4 billion entries. What was not mentioned in early news coverage on the 100 GB text file is that all these passwords came from previous leaks, said Steve Ragan, a security researcher at Akamai, a cybersecurity and cloud service company based in Cambridge, Mass.
“The list was released in April, and it is a word list containing a mix of previously leaked passwords and words, just basic words,” Ragan said. “It contains every word in Wikipedia, for example. Moreover, the previously leaked passwords are already known and have been known for years.”
These types of releases, when coupled with usernames, can be used for “credential stuffing,” a common attack used against financial institutions, according to Akamai. Credential stuffing is a form of automated attack where an attacker will run stolen passwords and usernames against an organization’s log in function until the attacker gains access to an active account. Once inside, Ragan explained, the attacker can steal money from the account or engage in money laundering.
Last year, Akamai saw 193 billion credential-stuffing attacks globally across its network, with 3.4 billion of those striking financial services organizations specifically. That’s an increase of more than 45% from 2019 in financial services, the security firm said in its 2021 “Phishing for finance” report, released last month.
There haven’t been enough data breaches to generate a list of RockYou2021’s size with only real passwords, Ragan added. The list is an example of a hacker trying to garner fame, he theorized. And it appears to have worked, given the publicity.
The addition of the word lists could be used to crack password hashes, which are when passwords have been scrambled, Ragan said. But even that was unlikely given “that those interested in such matters already have the source material that led to the creation of this list.”
Read more: How TD doubled down on automation for cybersecurity
Sander Vinberg, a threat research evangelist with F5 Labs, agreed with Ragan. F5 Labs is the research arm of the Seattle-based application security firm F5.
“On the surface, you look at this and you think, ‘There are so many credits here, this is a catastrophe,’” said Vinberg. “ I think that this is more of a big splash than a really big problem.”
Banks should not necessarily change their security posture because of RockYou2021, but they can set up alerts around the specific credentials in the release, Vinberg said.
“Anytime those show up in an authentication account, I would want to get a flag and be gathering more telemetry about the user agent, the machine and the user behind those attempts,” Vinberg said. “I view this as a small piece of intelligence that should be added to an existing program.”
Typically, by the time passwords are incorporated into leaks like RockYou2021, they’ve already been used by more advanced hackers, Vinberg added. Advanced hackers will generally release information only after they’ve used it, and before they think it will be released by someone else, he added. RockYou2021 was named after a famous password release from years ago that’s now used in training exercises, he added.
“These kinds of password drops that are re-collections of previous drops are not rare,” Vinberg said. “This happens pretty often.”
Bank Automation News will host a webinar on automation technology for better risk management and security on June 15 at 11:30 a.m. ET. Register here.






