Collection #1

High

About 773 million unique emails sat in this January 2019 compilation — not a single-company hack. Check whether your address is in the file, then treat any reused password as the first job.

772.9M
Records exposed
2019
Year
2
Data types
Free
To check
Check if you were affected — free

Quick answer — was Collection #1 breached?

No — Collection #1 is not a hack of one company. It is a January 2019 compilation of about 773 million unique email addresses and 21 million unique passwords gathered from more than 2,000 earlier incidents. A match means your address appeared in that compiled file. Check if you were affected.

What happened in the Collection #1 data breach?

In January 2019, researchers identified a massive compilation of previously leaked credentials — labelled Collection #1 — circulating on a popular hacking forum after a brief appearance on a public file host. After duplicates were stripped, the set contained about 773 million unique email addresses and about 21 million unique passwords, drawn from more than 2,000 earlier incidents. This was not a new hack of one company. It was a curated, ready-to-use list built for credential stuffing.

The passwords were already in usable form — cracked or taken from services that stored them poorly — so attackers did not need to break hashes first. Contemporary reporting put the raw file at about 87 GB, with more than a billion unique email-and-password pairs before further cleanup. A match does not name the original shop or app. It means that pair was in the compiled file and could be tried on other sites.

Independent analysis in January 2019 found that about 140 million email addresses and about 10 million passwords in Collection #1 had not appeared in previously published catalogs — likely smaller or never-disclosed incidents folded into the mix. Journalists who spoke with people selling the file said much of it was already two to three years old at the time, not a brand-new 2019 theft. Learn more about what a data breach means for you.

Why was the Collection #1 breach so dangerous?

The passwords were already in usable form — cracked or taken from services that stored them poorly — so attackers did not need to break hashes first. Contemporary reporting put the raw file at about 87 GB, with more than a billion unique email-and-password pairs before further cleanup. A match does not name the original shop or app. It means that pair was in the compiled file and could be tried on other sites.

Yes, if you still use a password that sat in that file. Collection #1 was assembled as a stuffing kit, then copied into later lists. As of 2026 it is old, widely mirrored, and still useful against reused logins. It does not expire. Changing the reused password and turning on two-factor authentication is the work — not “logging into Collection #1,” which is not a company.check whether your email was exposed in this breach.

What data was stolen in the Collection #1 breach?

Email addresses Passwords

Email addresses — used for phishing attacks and credential stuffing against your other accounts

Passwords — can be used to access your accounts directly or cracked to reveal your actual password

Timeline of the Collection #1 breach

2008–2018

Individual site breaches accumulate; cracked or poorly stored passwords are traded in underground markets

January 2019

Collection #1 appears as an ~87 GB archive on a public file host and a popular hacking forum

17 January 2019

Independent analysis published: about 773 million unique emails, about 21 million unique passwords, more than 2,000 source incidents

January 2019

Affected addresses added to public breach-notification catalogs so people could look up their own inbox

Late January 2019

The same markets advertise larger follow-on compilations — the same class of stuffing list, not a new single-company hack

2019–2026

Copies remain in credential-stuffing toolkits; leftover reused passwords from the file still unlock accounts

Is the Collection #1 breach still dangerous in 2026?

Yes, if you still use a password that sat in that file. Collection #1 was assembled as a stuffing kit, then copied into later lists. As of 2026 it is old, widely mirrored, and still useful against reused logins. It does not expire. Changing the reused password and turning on two-factor authentication is the work — not “logging into Collection #1,” which is not a company.

Email addresses in the file do not expire as phishing targets. A unique password plus two-factor authentication is what ages this list out of your life. Learn how long stolen data stays dangerous.

How is Collection #1 different from a site breach?

A site breach is one organisation’s failure: attackers copy that company’s user table, and the public name is usually the company. Collection #1 is a combolist — a combo list of email-and-password pairs stitched together from many older dumps, then de-duplicated so it is efficient to test.

That is why you should not look for a Collection #1 login page or a Collection #1 password-reset email. There is no customer support desk. The original source may have been a forgotten forum, a small shop, or a leak that was never announced. The stuffing kit is what survived.

Public coverage in January 2019 was consistent on the scale and the type: roughly 773 million unique inboxes, roughly 21 million unique passwords, an 87 GB archive, and no typical dump of payment cards or Social Security numbers. Later the same month, the same markets advertised larger follow-on compilations. Those later files are separate catalog rows when they appear. They are the same class of problem: reused passwords, not one new company hack.

  • Site breach — one named company, one incident date, a user database.
  • Combolist — many older incidents, one compiled file, built for automated login attempts.
  • A Collection #1 match is the second kind. Fix reuse. Do not hunt for a Collection #1 account.

How does EmailLeaked present a Collection #1 match?

If your address is in the compiled file, EmailLeaked shows a named match for Collection #1 the same way it shows a named company incident. The row is a lookup against industry-standard breach data sources — we do not claim an exclusive copy of the 2019 archive, and we do not crawl hidden markets live.

We present it as a compilation in this explainer so the result is not mistaken for “Collection #1 the company was hacked last week.” The checker still has to use the catalog name. This page is the plain-English layer: what the name means, what was typically in the file (email addresses and passwords), and which playbook to follow.

A match is not proof someone opened your laptop this week. It is evidence that the address — and often a password pair — appeared in a stuffing list that has been public for years. A miss is a snapshot of the records we can search today. We do not keep the address you type into the checker. Hosting logs and a privacy-oriented analytics beacon can still record that the page was visited.

If you want the response order in one place, use what to do after a data breach. If you want to test a reused password without sending the full password, use the password leak checker.

What to do if your email was in the Collection #1 breach

1

Confirm the match and what was listed

Run the email check again if you need the named incidents in one list. Collection #1 is a compiled file. Note whether passwords were listed. That decides how fast you move.

Check this email — free
2

Treat any reused password as public

You cannot log into Collection #1. Change the password on your email account and on every site that shared it. Then check whether that password appears in known leaks without sending the password itself.

3

Turn on two-factor authentication

Start with email. An authenticator app is stronger than a text-message code. A stuffing bot that has the password still fails if the second factor is not SMS sitting on a leaked phone number.

4

Follow the after-breach playbook

Use the first-hour and 24-hour lists, then the password vs email-only vs phone playbooks. A compilation match is usually the password playbook even when no single company name feels like yours.

Open the after-breach playbook
5

Retire logins you do not use

After the password work, close leftover accounts so an old forum password stops sitting around. That is hygiene, not a way to un-leak the 2019 file.

Browse delete-account guides

Frequently asked about the Collection #1 breach

What is Collection #1?
Collection #1 is a compilation of about 773 million unique email addresses and about 21 million unique passwords assembled from more than 2,000 earlier data breaches. It appeared in January 2019 as an ~87 GB archive. It was not a single hack of one company. It was packaged for credential-stuffing attacks.
Is Collection #1 a breach of one website?
No. It is a combolist — a combo list — built from many older dumps. There is no Collection #1 account to reset. The risk is any site where you reused a password that sat in that file.
Which of my accounts might be at risk from Collection #1?
Any service where you used an email and password pair that appeared in one of the source breaches. Because many passwords were already in plaintext, they could be tested on other sites immediately. Email, banking, and subscription logins are the usual targets.
My email appears in Collection #1 but not in any specific company breach — what does that mean?
The pair likely came from a smaller or never-announced incident that was folded into the compilation. About 140 million addresses in the 2019 analysis had not shown up in earlier public catalogs. You were still exposed. The original company name may never be known.
How does EmailLeaked show a Collection #1 match?
As a named row in the email checker, using industry-standard breach data sources. This explainer is the plain-English layer: it is a compilation, typically emails and passwords, and the next step is killing password reuse — not logging into a company called Collection #1. We do not claim exclusive ownership of the file.
Is Collection #1 still dangerous in 2026?
Yes, if the password has not been changed. The list is widely copied and still used in stuffing tools. The file does not expire. Unique passwords and two-factor authentication are what age it out of your life.

How this breach page is reviewed

Breach pages are built from structured breach records and reviewed for practical risk guidance by EmailLeaked. Risk labels reflect exposed data types and are intended to help readers prioritise action.

Was your email in this breach?

Check if your email appeared in the Collection #1 breach and 1033+ other known breaches — free, instant, no signup.

Check my email — free

No signup · Under 2 seconds · Never stored

Was my email hacked?

Check if your email is compromised in seconds. Free, private, no signup. Scan millions of breach records across 1034+ known breaches.

Check my email now — it's free

No signup required · Results in under 5 seconds · Your data is never stored