Research & InsightsCybersecurity

RockYou2024: what the biggest password leak in history means for you

Nearly ten billion passwords were published in one file. What that teaches us about identity security and the controls that still work.

FLYONIT Research Team22 July 20244 min read
Executive summary

The short version

The RockYou2024 compilation collected billions of previously leaked passwords into a single list that attackers now use to try logins at scale.

Passwords alone no longer protect an account. Multi-factor authentication and phishing-resistant sign-in are the practical defence.

Findings

What we found

1

Reused passwords are the real risk

A leaked password is only dangerous if it is still in use somewhere. Staff who reuse passwords across personal and work accounts expose the business.

2

Multi-factor authentication stops the vast majority of attacks

Accounts protected with a second factor resist password-list attacks almost entirely, which is why it is the first control we enable.

Recommendations

What to do next

  • Enforce multi-factor authentication for every user, with no exceptions for executives.
  • Block known-leaked passwords at the identity provider.
  • Roll out a password manager and move towards passwordless sign-in.

Methodology and sources

  • Analysis of the publicly reported RockYou2024 dataset, combined with identity attack patterns observed across FLYONIT-managed Microsoft 365 tenants.