Why Does Have I Been Pwned Contain "Fake" Email Addresses?
ID: 1a916f2e-28c5-5590-9c7f-5bc94d7330d8
STIX ID: report--1a916f2e-28c5-5590-9c7f-5bc94d7330d8
Feed Name: Troy Hunt – Security Blog
This post explains how HIBP ingests email addresses by applying simple syntactic rules (presence of @, valid domain/TLD, length constraints) and why seemingly fake addresses can appear in breach datasets. It notes many services store unverified emails during signup, allowing placeholders to persist and later show up in breaches, and demonstrates that genuinely random, unused addresses will not appear in HIBP. The author rebuts a critical review, emphasizing transparency and the operational limits of verifying billions of addresses.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
