Troy Hunt
Security researcher; founded Have I Been Pwned, and writes and speaks about data breaches.
Troy Hunt did not write this page. What is this?
It collects the places they publish and what they have said there, each linked to the source. They have no account here. Is this you? Claim it, correct it, or ask us to remove it from ppll.
Where they publish
Blog troyhunt.com His blog on breaches, passwords and web security. Has a feed.
Recent
- Weekly Update 521: Breach Perception v. Reality 11 Sept 2026 I think what really resonates with me this week is being able to completely turn the tables on perceptions around things like AI being the big bad hacking tool the news would have you believe. There's the stat I talk ab…
- Weekly Update 520: The Unscripted Edition 6 Sept 2026 I've started playing around with YouTube's "create video thumbnail", which hopefully will give me back a bit of time in my day (it used to be a manual job in Photoshop) and be a bit more interesting. And on that note, t…
- Weekly Update 519: Breaches & Data Integrity 1 Sept 2026 It does feel like I've bitten off too much and am now chewing like crazy this week. The 3D printing talk with Elle in Oslo, the "normal" NDC infosec talk, the cyber-broken talk with Scott in Copenhagen and then those ra…
Show 12 more
- A Cautionary Tale About Data Breach Claims, Verification and Carhartt 25 Aug 2026 You're not going to believe this, but turns out you can't always take criminals at their word. Actually, I'll walk that back a bit as it may not even be the cybercrime guys who got this wrong, but it all starts here: 🚨…
- Weekly Update 518: IoT Doorlock Nirvana with UniFi 24 Aug 2026 I genuinely think I've nailed the IoT door lock situation! Well, Ubiquiti has, but I think I've worked out how to put it all into a residential house and have it make sense. There are a few basic tenets: Main power (nev…
- Welcoming the Sri Lankan Government to Have I Been Pwned 23 Aug 2026 Today, we welcome the 48th government onboarded to Have I Been Pwned’s free gov service: Sri Lanka. Sri Lanka CERT now has access to monitor Sri Lankan government domains against the data in HIBP, helping identify expos…
- Weekly Update 517: Cyber Ransoms 18 Aug 2026 The current ransomware situation is a bit of a kludge (deep breath): a lot of ransomware (which often doesn't even involve "ware", it's just extortion) is carried out by kids who successfully make a truckload of money b…
- Weekly Update 516: Live From Vietnam 12 Aug 2026 A little wind noise, a little connectivity flakiness, and a little lip-sync issues from YouTube, but look at that view! 🤩 Back to business, it's the Brinks Home FAQ I found most interesting this week. I mean, how do yo…
- Welcoming the Nepalese Government to Have I Been Pwned 3 Aug 2026 Today, we welcome the 47th government onboarded to Have I Been Pwned’s free gov service: Nepal. Their National Cyber Security Centre now has access to monitor Nepalese government domains against the data in HIBP. This g…
- Weekly Update 515: Seeking Caffeine Utopia 3 Aug 2026 Apparently, Aussies are so obsessed with coffee that it's referred to as the coffee capital of the world down here (some bits, at least). "But what about Italy?" people ask. Having spent a lot of time in a lot of Italy,…
- Weekly Update 514: This Week in Data Breaches 26 Jul 2026 The Origin Energy breach down here in Aus is all over the news this week, and as with many breaches, it's multi-faceted. You've got them leading with "don't worry, your credit card is fine", the hacker leading with "the…
- Weekly Update 513: Clauding The Home Network 21 Jul 2026 I reckon this week's video on how Claude is tying together info from UniFi, Home Assistant and the Pi-Hole is an absolute ripper. Or at least the concept is - if ever there was an actual value proposition for AI it's ta…
- Weekly Update 512: IoT Lockout Fail 15 Jul 2026 "Build a smart home", they said. "It'll make life so much better", they said. Well, life wasn't very bloody good at 23:00 the other night after travelling 33 hours from Paris only to find the IoT doorlock batteries dead…
- Weekly Update 511: Live from my Riad in Marrakech 8 Jul 2026 How's this for a location?! I mean, last week was nice with Scott in Mallorca, but Marrakech is, well, wow 😮 Anyway, about those data breaches... This week I'm talking about the futility of attempting to remove piss fr…
- Swimming Pools, Pee, and Trying to Delete Your Data From the Internet 3 Jul 2026 I can't recall if someone else originally came up with this saying or if I said it in some off-the-cuff comment and it just propagated, but since it's often attributed back to me, I'll relay it here regardless: Trying t…
Link verified 20 Sept 2026. Recent items update automatically from the channel.
Mastodon @troyhunt@infosec.exchange Posts.
Recent
- We’re live from Oslo! Weekly update 522 with Scott Helme: 20 Sept 2026 youtube.com
- Weekly update is up! Breach Perception v. Reality: AI, Vishing, Odido, Manchester Airports Group, Sophistication, Published Keys, etc: 12 Sept 2026 troyhunt.com
- Going live with my weekly vid in 10 mins! Breach Perception v. Reality: AI, Vishing, Odido, Manchester Airports Group, Sophistication, Published Keys, etc 10 Sept 2026 youtube.com
Show 17 more
- RE: https://infosec.exchange/@ScottHelme/117229017209894413 Four years of exposure 😮 7 Sept 2026
- Weekly update is up! The Unscripted Edition: No agenda, all impromptu, here's what I'm up to, AMA, etc: 7 Sept 2026 troyhunt.com
- I'm live! Weekly Update 520: The Unscripted Edition: No agenda, all impromptu, here's what I'm up to, AMA, etc: 4 Sept 2026 youtube.com
- Weekly update is up! Breaches & Data Integrity: Synthetic Data in Breaches; Email Address != Person; Ridiculous Security for “Cyber Broken” Copenhagen: 2 Sept 2026 troyhunt.com
- Going live with my weekly vid in 10 mins! Breaches & Data Integrity: Synthetic Data in Breaches; Email Address != Person; Ridiculous Security for “Cyber Broken” Copenhagen 31 Aug 2026 youtube.com
- Just blogged: It's very easy to pull email addresses from a data breach and make claims about scope that are completely wrong. Like - MASSIVELY wrong - for example: 26 Aug 2026 troyhunt.com
- Weekly update is up! IoT Doorlock Nirvana with UniFi: All the UniFi Access Bits: Door Hub, Electric Strike, Drop Bolts, Readers, NFC Cards, Buttons, (and Much More): 24 Aug 2026 troyhunt.com
- We're very happy to welcome our 48th government CERT to @haveibeenpwned - Sri Lanka! 23 Aug 2026 troyhunt.com
- Going live with my weekly vid in 5 mins! All the UniFi Access Bits: Door Hub, Electric Strike, Drop Bolts, Readers, NFC Cards, Buttons, (and Much More) 20 Aug 2026 youtube.com
- Weekly update is up! Cyber Ransoms: Ransom Payments, Legalities, Reporting, Class Actions (and Everything Else) 18 Aug 2026 troyhunt.com
- Going live with my weekly vid in 10 mins! Cyber Ransoms: Ransom Payments, Legalities, Reporting, Class Actions (and Everything Else) 16 Aug 2026 youtube.com
- Weekly update is up! Live From Vietnam: ShinyHunters Ramping Back Up; New Breaches: Inter-Con Security, Exact Sciences, Brinks Home; The Breach Pipeline 13 Aug 2026 troyhunt.com
- Going live from Vietnam with my weekly vid in 10 mins! ShinyHunters Ramping Back Up; New Breaches: Inter-Con Security, Exact Sciences, Brinks Home; The Breach Pipeline: 13 Aug 2026 youtube.com
- We're very happy to welcome the 47th government to @haveibeenpwned, Nepal! Their National Cyber Security Centre now has free access to breach intelligence data affecting all their gov domains: 3 Aug 2026 troyhunt.com
- Weekly update is up! Seeking Caffeine Utopia: Levelling up the Coffee Game with Customised Synesso MVP Hydra; HIBP Roadmap - What Are We Missing? 3 Aug 2026 troyhunt.com
- Going live with my weekly vid in 5 mins! Weekly Update 515: Seeking Caffeine Utopia: Levelling up the Coffee Game with Customised Synesso MVP Hydra; HIBP Roadmap - What Are We Missing? 1 Aug 2026 youtube.com
- Weekly update is up! This Week in Data Breaches: Origin Energy, OpenAI & Hugging Face, Suno; Whatever Happened to ShinyHunters? 27 Jul 2026 troyhunt.com
Link verified 20 Sept 2026. Recent items update automatically from the channel.
Beliefs
Korrents What they believe 7 beliefs — each backed by an exact quote.
Each is a — compiled by korrents.com, not by them: the one-line wordings are korrents', the quotes are theirs.
Recent
A breached organisation owes its customers a fast and transparent disclosure, and that obligation applies to the person saying it too.
When I have conversations with breached companies, my messaging is crystal clear: be transparent and expeditious in your reporting of the incident and prioritise communicating with your customers.
A Sneaky Phish Just Grabbed my Mailchimp Mailing List Said 25 Mar 2025
A modern phish is automated end to end: the stolen credentials are used and the data exported within moments of being entered.
This was obviously highly automated and designed to immediately export the list before the victim could take preventative measures.
A Sneaky Phish Just Grabbed my Mailchimp Mailing List Said 25 Mar 2025
Every website needs HTTPS, including a static site with no login and nothing sensitive on it.
So that's precisely what I've done - intercepted my own traffic passed over an insecure connection and put together a string of demos in a 24-minute video explaining why HTTPS is necessary on a static website.
Here's Why Your Static Website Needs HTTPS Said 13 Jul 2018
Show 4 more
A password manager does not have to be perfect; it only has to be better than what people do without one.
password managers don't have to be perfect, they just have to be better than not having one.
Passwords Evolved: Authentication Guidance for the Modern Era Said 26 Jul 2017
Blocking paste on a password field makes passwords weaker, because people fall back to ones they can type.
When a website blocks the pasting of passwords in an attempt to improve security, they force some users to weaken their passwords to the point where they're dumbed down to easily typed versions.
Passwords Evolved: Authentication Guidance for the Modern Era Said 26 Jul 2017
Mandatory periodic password changes make passwords worse, because people just increment the number on the end.
If you're working in an environment that mandates regular password changes, you're very likely doing the same thing because it's an easy human control to deal with a technology requirement that's seen as an impediment.
Passwords Evolved: Authentication Guidance for the Modern Era Said 26 Jul 2017
Much of the received wisdom about passwords has been reversed, yet organisations still apply yesterday’s patterns to today’s threats.
In some cases, this has led to once-held "truths" about how we create and manage accounts to be totally flipped on their head, yet we still see modern organisations applying the patterns of yesterday to the threats of today.
Passwords Evolved: Authentication Guidance for the Modern Era Said 26 Jul 2017
Beliefs others hold too
Every website needs HTTPS, including a static site with no login and nothing sensitive on it. 2 hold this
So that's precisely what I've done - intercepted my own traffic passed over an insecure connection and put together a string of demos in a 24-minute video explaining why HTTPS is necessary on a static website.
Here's Why Your Static Website Needs HTTPS Said 13 Jul 2018
What is a korrent?
A korrent is a belief a person has stated in their own words: one sentence stating the claim, backed by a quote and a source, kept at korrents.com.
Under a name here, the quoted block is what they actually said. The korrent beneath it is the claim those words support, in korrents' wording — tap it to see the record, its source, and who else holds it.
Nobody here wrote their own korrents. They are compiled from public statements, and a person can change their mind, which is recorded too.
Feed
As its own page →Hiding
20 September
12 September
11 September
10 September
7 September
6 September
4 September
2 September
1 September
31 August
26 August
25 August
24 August
23 August
20 August
18 August
16 August
13 August
12 August
3 August
1 August
27 July
26 July
21 July
15 July
8 July
3 July
Nothing matches.
About the English under a post
Some people here publish in a language other than English. Where they do, this site shows a machine translation beneath the post, in this typeface — the site's own, not theirs.
The post itself is never changed, moved or hidden: what is set in the serif above is exactly what the person published, and it is what to quote them on. A translation can be wrong in ways that matter, especially about tone.
Only the post's own words are translated. A quoted post, a linked article and a belief on korrents.com are left in their original language.