NetEase data breach (2015)
In October 2015, a dataset attributed to the Chinese email provider NetEase (163.com and 126.com) surfaced, allegedly exposing around 234 million email addresses and plaintext passwords. NetEase denied any breach; HIBP lists the incident as unverified.
- Victim
- NetEase
- records
- 234.8M
- users
- 234.8M
In October 2015, a large dataset attributed to NetEase β the Chinese internet giant behind the popular 163.com and 126.com email services β was reported circulating online, allegedly exposing the credentials of roughly 234 million accounts.
What happened
The dataset was said to contain email addresses and plaintext passwords for NetEase users. Because the passwords were reportedly stored or distributed in clear text rather than hashed, any exposure would have been immediately usable β no cracking required. The data later surfaced on dark-web marketplaces, where it was offered for sale by cybercriminals.
Crucially, the breach has never been definitively confirmed. NetEase consistently denied that its systems had been compromised, maintaining that its infrastructure remained secure and that no unauthorized access had occurred. The company's limited communication drew criticism from the security community, leaving affected users without official guidance.
Verification status
Have I Been Pwned (HIBP) lists this incident as unverified. Verifying breaches involving Chinese companies is notoriously difficult: source attribution is murky, and the providers rarely cooperate. However, HIBP and other researchers noted that multiple individuals confirmed the authenticity of their own NetEase credentials within the leaked dataset, lending weight to the data's legitimacy even as the breach's origin remained disputed. The dataset was de-duplicated to roughly 234,842,089 records.
Impact
If genuine, the breach represents one of the largest credential exposures ever recorded, made far more dangerous by the alleged use of plaintext passwords. Email-and-password pairs are the raw material for credential-stuffing attacks: because users frequently reuse passwords, a NetEase dump could be replayed against banking, e-commerce, and other services worldwide. The contested status of the breach means many affected users likely never received notification or prompts to change their passwords.
Why it matters
The NetEase case highlights two recurring problems. First, plaintext password storage β if confirmed β is an indefensible practice that converts any data exposure into instant account takeover. Second, disputed and unverified mega-breaches complicate incident response: when a victim organization denies a breach that researchers and users partly corroborate, the people whose data is exposed are left in limbo, with no authoritative remediation guidance. It remains a cautionary example of how opacity around large breaches harms the very users they affect.
Timeline
A dataset of NetEase 163.com and 126.com accounts is reported circulating, allegedly containing email addresses and plaintext passwords.
The breach is dated by Have I Been Pwned, listing roughly 234 million affected accounts.
NetEase publicly denies that its systems were breached, stating its infrastructure remained secure.
Portions of the dataset surface on dark-web marketplaces, offered for sale by cybercriminals.
Multiple individuals confirm the authenticity of their NetEase credentials in the dataset, though HIBP keeps the breach flagged as unverified.
Sources
- haveibeenpwned.comhttps://haveibeenpwned.com/Breach/NetEase
- databreach.comhttps://databreach.com/breach/163.com-2015