Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
mass-credential-exposurecredential-stealer-activityleaked-secret-api-key

Massive Credential Exposure Reveals Billions of Stolen Login Records

Updated 29d agoFirst seen May 25, 20266 sources

Researchers and media reports disclosed enormous troves of exposed login data, including an unprotected 47.42 GB database containing 184,162,718 unique usernames and passwords tied to services such as Microsoft, Facebook, Google, Instagram, Snapchat, Discord, Netflix, PayPal, and government portals in 29 countries. Security researcher Jeremiah Fowler found the database on an unmanaged server with no password protection or encryption, and sample records included account types, website URLs, and plaintext passwords labeled senha. Fowler said multiple individuals confirmed the leaked credentials were genuine after he contacted them directly.

The exposed records are believed to be linked to infostealer malware and broader malware-as-a-service collection operations, with subsequent reporting describing a far larger cache totaling 16 billion credentials affecting major consumer platforms including Apple, Facebook, and Google. The disclosures raise immediate risks of credential stuffing, account takeover, phishing, fraud, and unauthorized access to corporate and government systems. Public access to the 184 million-record database was later restricted after responsible disclosure to the hosting provider, but the owner of the data remains unidentified.

Share:
Massive Credential Exposure Reveals Billions of Stolen Login Records
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

5 events from the most recent confirmed update back to the earliest known activity.

5 EVENTS
Jun 30, 20251y ago

Group-IB says 16 billion-password cache is recycled stealer-log data

Group-IB analyzed samples from the reported 16 billion-password dataset and concluded it was not a new mega-breach but a compilation of previously leaked stealer-log data, with decipherable credentials tracing to public leaks from 2021 to 2023. The firm said no sampled credential was first recorded in 2025, the newest verified compromise dated to April 2024, and it found no credible evidence that the full collection was being sold on dark-web markets at the time of analysis.

Is The Truth Behind The 16 Billion Passwords Leak Finally Revealed?
Jun 20, 20251y ago

Forbes reports broader 16 billion-password leak claims

Forbes published a report describing a much larger leak allegedly involving 16 billion passwords tied to Apple, Facebook, Google, and other services. Based on the provided reference, no additional underlying event details were available to determine whether this was the same dataset or a separate incident.

May 24, 20251y ago

Hosting provider restricts public access after disclosure

After Fowler responsibly disclosed the exposed database to World Host Group, public access to the server was restricted. The owner of the database remained unidentified.

Affected users confirm exposed credentials are authentic

Fowler contacted affected individuals to verify the data, and several confirmed that the exposed credentials matched their real passwords. This established that the database contained valid account information rather than fabricated or test data.

Researcher discovers exposed database with 184 million credentials

Cybersecurity researcher Jeremiah Fowler found an unprotected, non-encrypted 47.42 GB database containing 184,162,718 unique usernames and passwords. The records affected accounts tied to major platforms and government portals across 29 countries, and the dataset's structure suggested collection via infostealer malware.

The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.