CyberQP

Naz.API Leaks Data from Over 70 Million Accounts

A report by Troy Hunt revealed that Naz.API suffered a major data breach exposing over 70 million user accounts, highlighting significant cybersecurity risks.

Naz.API Leaks Data from Over 70 Million Accounts

Jim Jessup Profile Picture

Jim Jessup

COO & CO FOUNDER

Naz.API Leaks Data from Over 70 Million Accounts

Featured product tours

\ Duo for End-User Identity Verification | CyberQP Product Release

\ A Smarter, Faster CyberQP Onboarding and Deployment Experience

\ Local Admin & UAC Remediation in Agents | CyberQP Product Release

\ QTech Mobile App: End User Elevation Requests | CyberQP Product Release

How IT and Security Leaders can safeguard their admin access

Download eBook\ \

Published:

April 14, 2025

A report from Troy Hunt, the creator of the website Have I Been Pwned, alerted readers to a major data leak from Naz.API, a database containing data from over 70 million accounts and over a billion unique records. Hunt’s investigation has revealed “a significant volume of new data” and newly compromised accounts, and these accounts’ owners are at risk.

Naz.API stealer log example from Troy Hunt's report

According to the report, a “well-known,” unnamed technology firm discovered the dataset in a hacking forum post published in September 2023, through a bug bounty submission, and contacted Hunt with these details.

An investigation into these findings revealed that 34.97% (over one-third) of the email addresses in this dataset were new, and not available in Have I Been Pwned’s database. The report’s findings indicate that these credentials were compiled from infostealers exfiltrating credentials from compromised endpoints and environments, and data stolen in several credential stuffing attacks and previous breaches. (In fact, Hunt also recognized his own information from an illegal website that allowed threat actors to search for people’s data.)

The report also shared a screenshot of the stealer logs, which contained a URL to login, an email address to log in, and the password in his findings.

In total, Hunt identified 319 files, with a total file size of 104 GB. He was also able to verify that the credentials were real by contacting several people listed in these infostealer logs, and by using website password request forms or registration forms to confirm that the email address exists in their account bases.

Are you rotating your credentials?

The size of this data leak poses a major risk to MSPs and end users alike, and truly emphasizes the risks associated with stale or reused credentials and standing privilege, such as persistent admin accounts.

Are you implementing zero standing privilege?

That’s why security best practices require individuals and organizations to mitigate their risk by regularly rotating critical credentials, and limiting privileged access through solutions like Just-in-Time access.

CyberQP’s security experts recommend that concerned MSPs and end users take the following actions to mitigate their risk:

  • Check if your data has been compromised with a service like Have I Been Pwned.
  • Add another layer of protection to your key accounts, including complex passwords or passphrases and multi-factor authentication (MFA).
  • For privileged accounts, utilize a password vault and implement additional protection, such as end user identity verification.
  • MSPs can implement a moving target defense for their privileged accounts by regularly rotating credentials to deter threat actors and prevent them from achieving a foothold in your environment or executing lateral movement attacks.
  • MSPs can also reduce their attack surface with Just-in-Time accounts that only grant privileged access for the amount of time a user needs it. Solutions like these also enable them to meet compliance and cyber insurance best practices by achieving zero standing privilege.

Source: Troy Hunt, Inside the Massive Naz.API Credential Stuffing List.

CyberQP builds privileged access management for MSPs and IT teams: credential vaulting and rotation, just-in-time access, and help desk identity verification. Take a product tour or book a demo.

Don't miss these

See all blogs

Quickpass Rebrands to CyberQP, Raises $12M to Help MSPs with Privileged Access Management.\ \ Blog post\ \ PRESS\ \ Quickpass Rebrands to CyberQP, Raises $12M to Help MSPs with Privileged Access Management. \ \ April 24, 2023

Naz.API Leaks Data from Over 70 Million Accounts\ \ Blog post\ \ Naz.API Leaks Data from Over 70 Million Accounts \ \ April 14, 2025

It is 2026. Is Your Privileged Password Rotation Still Not Automated\ \ Blog post\ \ It is 2026. Is Your Privileged Password Rotation Still Not Automated \ \ November 13, 2025

Products

Pricing QGuard QDesk Integrations Product Tours Product Roadmap Release Notes

Products

Submit a Ticket Partner Portal Trust Center Knowledge Base

Company

Company Leadership Contact Careers

Resources

Resource Hub Blog White Papers eBooks Webinars Success Stories

CyberQP Monochrome LogoCCPA Compliant, SOC 2 Type 2 Certifies, GDPR Compliant Badges

© 2026 CyberQP Inc. All rights reserved.

Privacy Policy Terms & Conditions Cookie Policy Consent Preferences