3 ms·
You don’t know that they weren’t. HIBP is not omniscient. It doesn’t automatically get a list of leaked account info unless that info is published publically. B
by dpkonofa 3y ago
You don’t know that they weren’t. HIBP is not omniscient. It doesn’t automatically get a list of leaked account info unless that info is published publically. Based on the current evidence I’ve seen so far, that’s not the case. It seems like the breached data was sold privately on the dark web and was tested for months via a botnet. It also seems like the leaked data included either IPs or last known login location info which means someone with a sizable enough botnet could have used that info to login from nearby locations, thereby bypassing any prompts triggered by “new locations”.