Skip to main content
Home > What Are the Latest Developments with Intercede’s Password Breach Database?

What Are the Latest Developments with Intercede’s Password Breach Database?

How the world’s largest actively managed breach database keeps getting bigger, and why it matters

▶ WATCH THE VIDEO

This blog post accompanies our video update on Intercede’s Password Breach Database, where our team walks through the latest 2025 developments, the staggering growth in compromised credentials, shifting distribution channels, and what it all means for your organisation’s security posture. Watch the full video for the complete breakdown.

A Growing Problem Demands a Growing Solution

Data breaches are not slowing down. If anything, the volume and sophistication of credential theft is accelerating. That is why Intercede continues to invest heavily in its Password Breach Database, the world’s largest actively managed repository of compromised credentials, to ensure organisations have the intelligence they need to protect their users. In our latest video, we take a detailed look at the 2025 updates and what they reveal about the current threat landscape.

The Numbers

In 2025, Intercede imported 1 billion newly discovered credentials into the database, bringing the total to over 11 billion breached credentials. The team also added 376 million unique passwords never seen before, pushing the overall unique password count to 3.8 billion. The database receives approximately four million breach updates daily, ensuring it stays current with the rapidly evolving threat landscape. As our experts discuss in the video, these numbers reflect just how prolific credential theft has become.

Where Do Breached Credentials Come From?

The threat intelligence team monitors a wide range of sources across the surface, deep, and dark web. In 2025, four primary distribution channels dominated: forums, Telegram, cloud-based combolists, and stealer logs. Notably, by mid-year, Telegram overtook forums as the preferred platform for sharing breached data, thanks to its end-to-end encryption, anonymity features, and monetisation capabilities. Our video goes into this shift in detail, explaining what it means for the threat landscape.

The data is gathered from mainstream news outlets, online forums, torrents, paste bins, and other areas of the dark web by Intercede’s dedicated team of ethical hackers and security researchers.

Why This Matters for Your Organisation

Most people reuse passwords across multiple services. When a credential is exposed in one breach, it becomes a weapon that attackers can use against every other service where that person used the same password. By checking employee and user passwords against the Intercede database, organisations can proactively identify compromised credentials before attackers exploit them.

How It Works in Practice

Intercede’s Password Breach Database is available through MyID PSM (Password Security Management) and via a developer-friendly API. It integrates with Active Directory and other identity platforms to provide continuous monitoring, alerting administrators when user credentials appear in a breach and prompting users to change compromised passwords. The result is a significant reduction in credential-based attack risk and a measurable decrease in help-desk costs from password resets.

Looking Ahead

As breach volumes continue to grow and distribution channels evolve, Intercede remains committed to maintaining the most comprehensive and up-to-date breach intelligence available. It is a critical layer of defence in any organisation’s authentication strategy.

▶ WATCH THE FULL DISCUSSION

For the full 2025 breach landscape review, including how Telegram overtook forums, the rise of stealer logs, and a live look at the database in action, watch our video: “What Are the Latest Developments with Intercede’s Password Breach Database.”