Skip to content
Data breachResolved

NetEase data breach (2015)

In October 2015, a dataset attributed to the Chinese email provider NetEase (163.com and 126.com) surfaced, allegedly exposing around 234 million email addresses and plaintext passwords. NetEase denied any breach; HIBP lists the incident as unverified.

Victim
NetEase
records
234.8M
users
234.8M

In October 2015, a large dataset attributed to NetEase β€” the Chinese internet giant behind the popular 163.com and 126.com email services β€” was reported circulating online, allegedly exposing the credentials of roughly 234 million accounts.

What happened

The dataset was said to contain email addresses and plaintext passwords for NetEase users. Because the passwords were reportedly stored or distributed in clear text rather than hashed, any exposure would have been immediately usable β€” no cracking required. The data later surfaced on dark-web marketplaces, where it was offered for sale by cybercriminals.

Crucially, the breach has never been definitively confirmed. NetEase consistently denied that its systems had been compromised, maintaining that its infrastructure remained secure and that no unauthorized access had occurred. The company's limited communication drew criticism from the security community, leaving affected users without official guidance.

Verification status

Have I Been Pwned (HIBP) lists this incident as unverified. Verifying breaches involving Chinese companies is notoriously difficult: source attribution is murky, and the providers rarely cooperate. However, HIBP and other researchers noted that multiple individuals confirmed the authenticity of their own NetEase credentials within the leaked dataset, lending weight to the data's legitimacy even as the breach's origin remained disputed. The dataset was de-duplicated to roughly 234,842,089 records.

Impact

If genuine, the breach represents one of the largest credential exposures ever recorded, made far more dangerous by the alleged use of plaintext passwords. Email-and-password pairs are the raw material for credential-stuffing attacks: because users frequently reuse passwords, a NetEase dump could be replayed against banking, e-commerce, and other services worldwide. The contested status of the breach means many affected users likely never received notification or prompts to change their passwords.

Why it matters

The NetEase case highlights two recurring problems. First, plaintext password storage β€” if confirmed β€” is an indefensible practice that converts any data exposure into instant account takeover. Second, disputed and unverified mega-breaches complicate incident response: when a victim organization denies a breach that researchers and users partly corroborate, the people whose data is exposed are left in limbo, with no authoritative remediation guidance. It remains a cautionary example of how opacity around large breaches harms the very users they affect.

Timeline

  1. A dataset of NetEase 163.com and 126.com accounts is reported circulating, allegedly containing email addresses and plaintext passwords.

  2. The breach is dated by Have I Been Pwned, listing roughly 234 million affected accounts.

  3. NetEase publicly denies that its systems were breached, stating its infrastructure remained secure.

  4. Portions of the dataset surface on dark-web marketplaces, offered for sale by cybercriminals.

  5. Multiple individuals confirm the authenticity of their NetEase credentials in the dataset, though HIBP keeps the breach flagged as unverified.

Sources

  1. haveibeenpwned.comhttps://haveibeenpwned.com/Breach/NetEase
  2. databreach.comhttps://databreach.com/breach/163.com-2015

Related incidents

Data breachResolved

Sina Weibo data leak

Personal data on 538 million Sina Weibo accounts β€” including the phone numbers of 172 million users β€” was offered for sale on the dark web for about $250, in a leak Weibo attributed to address-book matching abuse dating back to 2018. China's industry ministry summoned the company over its handling of personal data.

Victim
Sina Weibo
Records
538.0M
Data breachResolved

Tianya data breach (2011)

In December 2011, China's largest online forum known as Tianya was hacked and tens of millions of accounts were obtained by the attacker. The leaked data included names, usernames and email addresses.

Victim
Tianya
Records
29.0M
Data breachResolved

QuinStreet data breach (2015)

In approximately late 2015, the maker of "performance marketing products" QuinStreet had a number of their online assets compromised. The attack impacted 28 separate sites, predominantly technology forums such as flashkit.com, codeguru.com and webdeveloper.com (view a full list of sites).

Victim
QuinStreet
Records
4.9M
Data breachResolved

Nihonomaru data breach (2015)

In late 2015, the anime community known as Nihonomaru had their vBulletin forum hacked and 1.7 million accounts exposed. The compromised data included email and IP addresses, usernames and salted hashes of passwords.

Victim
Nihonomaru
Records
1.7M