logo

Why Does Have I Been Pwned Contain "Fake" Email Addresses?

ID: 1a916f2e-28c5-5590-9c7f-5bc94d7330d8

STIX ID: report--1a916f2e-28c5-5590-9c7f-5bc94d7330d8

Feed Name: Troy Hunt – Security Blog

Date Published: 2025-12-03

Date Updated: 2026-04-19

Author: Troy Hunt

...
...

This post explains how HIBP ingests email addresses by applying simple syntactic rules (presence of @, valid domain/TLD, length constraints) and why seemingly fake addresses can appear in breach datasets. It notes many services store unverified emails during signup, allowing placeholders to persist and later show up in breaches, and demonstrates that genuinely random, unused addresses will not appear in HIBP. The author rebuts a critical review, emphasizing transparency and the operational limits of verifying billions of addresses.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.