24 billion records exposed in massive data leak

Cybersecurity researchers have uncovered a massive cloud-based repository containing 24 billion leaked records, making it one of the largest aggregations of stolen credentials ever discovered.
The data leak, which was identified on June 12 by the research team at Cybernews, exposed tens of billions of unique usernames, email addresses, and plaintext passwords.
Worryingly, the records also included the precise website URLs that the credentials were meant to unlock, providing bad actors with an explicit roadmap for hacking.
The multi-terabyte database was left completely unprotected on a publicly accessible Elasticsearch cluster – a network of interconnected search servers. In total, the scale of the exposed data exceeded 8.3 terabytes.
According to the Cybernews research team, the cluster does not appear to be a traditional corporate data breach. Instead, evidence strongly indicates it is a central repository for “infostealer log databases.”

Infostealer malware is a type of malicious software secretly downloaded by users through corrupted files, infected PDFs, or pirated software. Once a device is compromised, the malware silently extracts autofill data, stored credentials, credit card details and crypto wallet keys from web browsers without the victim’s knowledge.
The architecture of the exposed server reveals a highly organised criminal operation. The credentials were saved in a raw format, with each login detail listed separately. While Cybernews has been unable to identify the administrator of the database, the logs were collected from 36 distinct channels, including over 1.7 billion records harvested from hacking-oriented Telegram groups.
Serious risk of takeover
While the server has since been secured and is no longer publicly exposed, the timeline of the data remains partially unclear. Researchers noted that because the database contained a news article from February 2026, the operator was actively updating the cluster with fresh information right up until its discovery.
“Billions of affected accounts are at serious risk of takeovers, especially if they are not protected with multi-factor authentication,” the Cybernews team explained.
Security experts warn that the leak will likely fuel a massive wave of credential-stuffing attacks, where hackers automate bots to test leaked password combinations across retail, banking, and social media platforms. Users are strongly urged to change compromised passwords immediately and implement multi-factor authentication (MFA) to lock down their digital footprints.
Discover more from Tech Digest
Subscribe to get the latest posts sent to your email.
