About 164.6 million email addresses sat in the 2012 LinkedIn password file that resurfaced in 2016. Check whether your address is in that file, then treat any reused password as the first job.
Quick answer — was LinkedIn breached?
Yes — this page is the 2012 LinkedIn password-database theft, later sold in 2016 as about 164 million email-and-hash pairs. It is not the 2021 public-profile scrape. A match means your address appeared in that credential file. Check if you were affected.
What happened in the LinkedIn data breach?
This catalog row is the 2012 LinkedIn password-database theft — not the later public-profile scrapes. In June 2012, about 6.5 million unsalted SHA-1 password hashes appeared on a public forum. LinkedIn confirmed a breach. In May 2016 the same incident resurfaced as a sale of about 164 million email addresses paired with those hashes. Independent analysis of the 2016 file put the unique-email count in this catalog at about 164.6 million.
The hashes were SHA-1 without a salt, so identical passwords produced identical hashes and cracked in bulk. Password-recovery researchers reported cracking well over 80 percent of the unique hashes within days of the 2016 release. Those plaintext passwords were then useful anywhere the same login had been reused — not only on LinkedIn. The professional email addresses also remain a reliable hook for business-themed phishing.
LinkedIn later said it invalidated passwords for accounts created before the 2012 breach that had not been updated since. That closes the LinkedIn login. It does not close any other site where the same password was still in use. Learn more about what a data breach means for you.
Why was the LinkedIn breach so dangerous?
The hashes were SHA-1 without a salt, so identical passwords produced identical hashes and cracked in bulk. Password-recovery researchers reported cracking well over 80 percent of the unique hashes within days of the 2016 release. Those plaintext passwords were then useful anywhere the same login had been reused — not only on LinkedIn. The professional email addresses also remain a reliable hook for business-themed phishing.
Yes, if that 2012 password was ever reused and has not been changed. The file is old, widely copied, and still useful for credential stuffing. A unique LinkedIn password plus an authenticator-app second factor is what ages this incident out of your life. Changing the LinkedIn password does not retire the same string on email, banking, or shopping sites.check whether your email was exposed in this breach.
What data was stolen in the LinkedIn breach?
Email addresses — used for phishing attacks and credential stuffing against your other accounts
Passwords — can be used to access your accounts directly or cracked to reveal your actual password
Timeline of the LinkedIn breach
June 2012
About 6.5 million unsalted SHA-1 password hashes from LinkedIn appear on a public forum; LinkedIn confirms a breach
June 2012
Researchers confirm the hashes have no salt; common passwords crack quickly because identical passwords share a hash
May 2016
A much larger file from the same 2012 incident is offered for sale — on the order of 164–167 million email-and-hash pairs
May 2016
Independent analysis of the circulating file; password-recovery researchers report cracking well over 80 percent of unique hashes within days
May 2016
LinkedIn says it invalidated passwords for pre-2012 accounts that had not been updated since the original incident
2016–2026
Copies remain in credential-stuffing lists; leftover reused passwords from the file still unlock other sites
Is the LinkedIn breach still dangerous in 2026?
Yes, if that 2012 password was ever reused and has not been changed. The file is old, widely copied, and still useful for credential stuffing. A unique LinkedIn password plus an authenticator-app second factor is what ages this incident out of your life. Changing the LinkedIn password does not retire the same string on email, banking, or shopping sites.
Email addresses from 2012 do not expire as phishing targets. A unique password plus two-factor authentication is the work — not waiting for LinkedIn to “recall” the 2016 sale. Learn how long stolen data stays dangerous.
How is the 2012 LinkedIn breach different from later scrapes?
A password-database theft and a public-profile scrape are different failures. In 2012 attackers copied LinkedIn’s stored password hashes and, when the fuller file appeared in 2016, the matching email addresses. That is a credential incident: the risk is login reuse.
In 2021, and again in a 2023 scraped-and-faked set, operators collected information that was already visible on public profiles — names, job titles, locations — and sometimes guessed or appended email addresses. Those later files are separate catalog rows. They do not include the 2012 password hashes, and this page does not pretend they do.
If you want the “is the site safe to use now?” question, use Is LinkedIn safe after the data breach?. This page stays on the 2012 credential file that industry-standard breach data sources list under the LinkedIn name.
- 2012 / 2016 file — emails and unsalted SHA-1 password hashes. Fix reuse.
- 2021 and 2023 scrapes — mostly public profile fields. Different rows, different playbook.
- A match on this page is the first kind. Do not assume a scrape-only exposure.
What does an EmailLeaked LinkedIn match mean?
If your address is in the 2012 credential file, EmailLeaked shows a named LinkedIn match the same way it shows any other named incident. The row is a lookup against industry-standard breach data sources. We do not claim an exclusive copy of the 2016 sale, and we do not crawl hidden markets live.
A match is not proof someone opened your LinkedIn session this week. It is evidence that the address — and typically a password hash from that era — appeared in a file that has been public for years. A miss is a snapshot of the records we can search today. We do not keep the address you type into the checker. Hosting logs and a privacy-oriented analytics beacon can still record that the page was visited.
If you want the response order in one place, use what to do after a data breach. If you want to test a reused password without sending the full password, use the password leak checker. For a second public index, see free data breach checkers.
What to do if your email was in the LinkedIn breach
Confirm the match and what was listed
Run the email check if you need the named incidents in one list. This LinkedIn row lists email addresses and passwords. That is the password playbook, not a profile-scrape playbook.
Check this email — freeTreat any reused password as public
Change the password on LinkedIn and on every site that shared it — starting with email. Then check whether that password appears in known leaks without sending the password itself.
Turn on two-factor authentication
Start with email, then LinkedIn. An authenticator app is stronger than a text-message code. A stuffing bot that has the 2012 password still fails if the second factor is not sitting on a leaked phone number.
Follow the after-breach playbook
Use the first-hour and 24-hour lists, then the password playbook. Walk the account security checklist so recovery email, sessions, and leftover logins get a pass.
Open the after-breach playbookCompare how public checkers differ
A second lookup does not change the 2012 file. It can show you how different public indexes present the same named incident.
Read the checker comparisonClose LinkedIn if you no longer use it
Deletion does not unsay the 2012 file. It stops an old professional login and recovery email from sitting around. Use the official close steps, then lock the inbox that still recovers other accounts.
How to delete your LinkedIn accountFrequently asked about the LinkedIn breach
What happened in the LinkedIn data breach this page covers?
Were LinkedIn passwords really cracked?
Why did it take four years to see the full file?
How is this different from later LinkedIn scraping incidents?
How does EmailLeaked show a LinkedIn match?
Is the LinkedIn breach still dangerous in 2026?
How this breach page is reviewed
Breach pages are built from structured breach records and reviewed for practical risk guidance by EmailLeaked. Risk labels reflect exposed data types and are intended to help readers prioritise action.
Sources
Last updated: September 2026
Other major breaches
Was your email in this breach?
Check if your email appeared in the LinkedIn breach and 1033+ other known breaches — free, instant, no signup.
Check my email — freeWas my email hacked?
Check if your email is compromised in seconds. Free, private, no signup. Scan millions of breach records across 1034+ known breaches.
Check my email now — it's freeNo signup required · Results in under 5 seconds · Your data is never stored