About 773 million unique emails sat in this January 2019 compilation — not a single-company hack. Check whether your address is in the file, then treat any reused password as the first job.
Quick answer — was Collection #1 breached?
No — Collection #1 is not a hack of one company. It is a January 2019 compilation of about 773 million unique email addresses and 21 million unique passwords gathered from more than 2,000 earlier incidents. A match means your address appeared in that compiled file. Check if you were affected.
What happened in the Collection #1 data breach?
In January 2019, researchers identified a massive compilation of previously leaked credentials — labelled Collection #1 — circulating on a popular hacking forum after a brief appearance on a public file host. After duplicates were stripped, the set contained about 773 million unique email addresses and about 21 million unique passwords, drawn from more than 2,000 earlier incidents. This was not a new hack of one company. It was a curated, ready-to-use list built for credential stuffing.
The passwords were already in usable form — cracked or taken from services that stored them poorly — so attackers did not need to break hashes first. Contemporary reporting put the raw file at about 87 GB, with more than a billion unique email-and-password pairs before further cleanup. A match does not name the original shop or app. It means that pair was in the compiled file and could be tried on other sites.
Independent analysis in January 2019 found that about 140 million email addresses and about 10 million passwords in Collection #1 had not appeared in previously published catalogs — likely smaller or never-disclosed incidents folded into the mix. Journalists who spoke with people selling the file said much of it was already two to three years old at the time, not a brand-new 2019 theft. Learn more about what a data breach means for you.
Why was the Collection #1 breach so dangerous?
The passwords were already in usable form — cracked or taken from services that stored them poorly — so attackers did not need to break hashes first. Contemporary reporting put the raw file at about 87 GB, with more than a billion unique email-and-password pairs before further cleanup. A match does not name the original shop or app. It means that pair was in the compiled file and could be tried on other sites.
Yes, if you still use a password that sat in that file. Collection #1 was assembled as a stuffing kit, then copied into later lists. As of 2026 it is old, widely mirrored, and still useful against reused logins. It does not expire. Changing the reused password and turning on two-factor authentication is the work — not “logging into Collection #1,” which is not a company.check whether your email was exposed in this breach.
What data was stolen in the Collection #1 breach?
Email addresses — used for phishing attacks and credential stuffing against your other accounts
Passwords — can be used to access your accounts directly or cracked to reveal your actual password
Timeline of the Collection #1 breach
2008–2018
Individual site breaches accumulate; cracked or poorly stored passwords are traded in underground markets
January 2019
Collection #1 appears as an ~87 GB archive on a public file host and a popular hacking forum
17 January 2019
Independent analysis published: about 773 million unique emails, about 21 million unique passwords, more than 2,000 source incidents
January 2019
Affected addresses added to public breach-notification catalogs so people could look up their own inbox
Late January 2019
The same markets advertise larger follow-on compilations — the same class of stuffing list, not a new single-company hack
2019–2026
Copies remain in credential-stuffing toolkits; leftover reused passwords from the file still unlock accounts
Is the Collection #1 breach still dangerous in 2026?
Yes, if you still use a password that sat in that file. Collection #1 was assembled as a stuffing kit, then copied into later lists. As of 2026 it is old, widely mirrored, and still useful against reused logins. It does not expire. Changing the reused password and turning on two-factor authentication is the work — not “logging into Collection #1,” which is not a company.
Email addresses in the file do not expire as phishing targets. A unique password plus two-factor authentication is what ages this list out of your life. Learn how long stolen data stays dangerous.
How is Collection #1 different from a site breach?
A site breach is one organisation’s failure: attackers copy that company’s user table, and the public name is usually the company. Collection #1 is a combolist — a combo list of email-and-password pairs stitched together from many older dumps, then de-duplicated so it is efficient to test.
That is why you should not look for a Collection #1 login page or a Collection #1 password-reset email. There is no customer support desk. The original source may have been a forgotten forum, a small shop, or a leak that was never announced. The stuffing kit is what survived.
Public coverage in January 2019 was consistent on the scale and the type: roughly 773 million unique inboxes, roughly 21 million unique passwords, an 87 GB archive, and no typical dump of payment cards or Social Security numbers. Later the same month, the same markets advertised larger follow-on compilations. Those later files are separate catalog rows when they appear. They are the same class of problem: reused passwords, not one new company hack.
- Site breach — one named company, one incident date, a user database.
- Combolist — many older incidents, one compiled file, built for automated login attempts.
- A Collection #1 match is the second kind. Fix reuse. Do not hunt for a Collection #1 account.
How does EmailLeaked present a Collection #1 match?
If your address is in the compiled file, EmailLeaked shows a named match for Collection #1 the same way it shows a named company incident. The row is a lookup against industry-standard breach data sources — we do not claim an exclusive copy of the 2019 archive, and we do not crawl hidden markets live.
We present it as a compilation in this explainer so the result is not mistaken for “Collection #1 the company was hacked last week.” The checker still has to use the catalog name. This page is the plain-English layer: what the name means, what was typically in the file (email addresses and passwords), and which playbook to follow.
A match is not proof someone opened your laptop this week. It is evidence that the address — and often a password pair — appeared in a stuffing list that has been public for years. A miss is a snapshot of the records we can search today. We do not keep the address you type into the checker. Hosting logs and a privacy-oriented analytics beacon can still record that the page was visited.
If you want the response order in one place, use what to do after a data breach. If you want to test a reused password without sending the full password, use the password leak checker.
What to do if your email was in the Collection #1 breach
Confirm the match and what was listed
Run the email check again if you need the named incidents in one list. Collection #1 is a compiled file. Note whether passwords were listed. That decides how fast you move.
Check this email — freeTreat any reused password as public
You cannot log into Collection #1. Change the password on your email account and on every site that shared it. Then check whether that password appears in known leaks without sending the password itself.
Turn on two-factor authentication
Start with email. An authenticator app is stronger than a text-message code. A stuffing bot that has the password still fails if the second factor is not SMS sitting on a leaked phone number.
Follow the after-breach playbook
Use the first-hour and 24-hour lists, then the password vs email-only vs phone playbooks. A compilation match is usually the password playbook even when no single company name feels like yours.
Open the after-breach playbookRetire logins you do not use
After the password work, close leftover accounts so an old forum password stops sitting around. That is hygiene, not a way to un-leak the 2019 file.
Browse delete-account guidesFrequently asked about the Collection #1 breach
What is Collection #1?
Is Collection #1 a breach of one website?
Which of my accounts might be at risk from Collection #1?
My email appears in Collection #1 but not in any specific company breach — what does that mean?
How does EmailLeaked show a Collection #1 match?
Is Collection #1 still dangerous in 2026?
How this breach page is reviewed
Breach pages are built from structured breach records and reviewed for practical risk guidance by EmailLeaked. Risk labels reflect exposed data types and are intended to help readers prioritise action.
Sources
Last updated: September 2026
Other major breaches
Was your email in this breach?
Check if your email appeared in the Collection #1 breach and 1033+ other known breaches — free, instant, no signup.
Check my email — freeWas my email hacked?
Check if your email is compromised in seconds. Free, private, no signup. Scan millions of breach records across 1034+ known breaches.
Check my email now — it's freeNo signup required · Results in under 5 seconds · Your data is never stored