Security researchers uncovered a single online trove holding roughly 24 billion stolen credential records, one of the largest collections of leaked login data ever documented. The database sat on the open internet with no password protecting it, meaning anyone who located the address could browse billions of usernames and passwords with nothing more than a web browser. The find, disclosed in the middle of 2026, reads less like a fresh corporate hack than a snapshot of how thoroughly stolen credentials now circulate as a tradable commodity.
What was inside the 24 billion records
The scale of the find is easier to grasp through its raw size than its record count. The collection weighed in at about 8.3 terabytes and contained usernames, email addresses, plaintext passwords, login URLs and source tags that labeled where each set had come from. Plaintext passwords are especially dangerous because they require no cracking to use, and the accompanying login URLs point an attacker straight at the exact service each credential is meant to unlock. Session tokens found in similar dumps can, in some cases, let an intruder slip into an account without the password at all, bypassing the login screen entirely.
The discovery was made by researchers who found the exposed database and verified its contents before it disappeared from public view. Their analysis, reported in detail by Cybernews, traced the data back to dozens of separate origins rather than a single hacked company. Security firm Malwarebytes flagged the dump as one of the largest ever seen and urged people to check whether their credentials were caught up in it. Roughly 22.6 billion of the records were categorized as compiled “collections,” sets stitched together from historical breach events, while the remainder traced back to fresher malware logs.
Why it was a consolidation, not a single breach
Despite the enormous number, no single service lost 24 billion accounts. The trove was a consolidation assembled from 36 sources, including Telegram channels used to trade stolen data, older breach compilations and fresh logs harvested by malware. In practice that means the same person can appear many times over, with credentials for different sites gathered from different incidents. The danger of these aggregated sets is not novelty but convenience: they hand criminals a single, searchable index of years of theft, sorted and tagged so a specific target or a specific website can be looked up in seconds. Framed that way, the discovery is less a data-breach story than a milestone, marking the point at which credential theft stopped being a scattered nuisance and became an industrial supply chain.
How infostealer malware feeds these dumps
A large share of the records originated with infostealers, a category of malware built to quietly scrape saved passwords, browser data and authentication tokens from infected devices. Once harvested, those logs are sold and resold across criminal marketplaces and messaging channels, then periodically merged into mega-collections like this one. Because infostealers pull credentials straight from a victim’s own machine, they capture whatever has been saved in a browser, which is why a single infection can compromise dozens of accounts at once. The malware often arrives disguised as cracked software, a fake update or a malicious email attachment, and it can operate silently for months, siphoning new logins as they are typed and quietly forwarding them to whoever deployed it.
How credential stuffing turns the dump into break-ins
A collection this size is valuable to attackers mainly as fuel for credential stuffing, an automated technique that feeds stolen username-and-password pairs into login forms across many sites at once. Because so many people recycle the same password, even a low success rate against 24 billion records translates into millions of compromised accounts. Automated tools can test enormous credential lists against banking portals, email providers and retail logins within hours, and the labeled login URLs in this trove remove even the guesswork of matching a password to the right site. Security analysts have warned that aggregated sets like this one shorten the distance between a years-old breach and a brand-new account takeover, since the same leaked login can be retried indefinitely until someone finally changes it or an extra layer of protection blocks the attempt.
The exposed database and its removal
The trove was stored in an Elasticsearch database left open to the internet, a common misconfiguration that repeatedly exposes sensitive data. Researchers spotted the cluster on June 12, 2026, and it was reported secured by June 15, a narrow window that nonetheless left ample time for anyone watching the same open internet to copy what was inside. The removal limits casual access, but it offers no guarantee that copies were not already downloaded, so the credentials should be treated as permanently compromised. Open, unauthenticated databases have surfaced repeatedly in recent years, and each incident underscores how a single overlooked configuration setting can put billions of records within reach of an automated scan.
Reducing the risk from leaked credentials
The practical response to a dump this size is to assume exposure rather than hope for the best. Reusing a single password across sites is what makes these collections so powerful, because one leaked login becomes a master key to every account sharing it. Switching to unique passwords managed by a password manager, turning on multifactor authentication and running a reputable malware scan to catch any active infostealer all shrink the blast radius. Even where a password has already leaked, a second verification step can stop most automated takeover attempts cold, which is why security teams treat multifactor authentication as the single highest-value habit against exactly this kind of exposure. Checking an email address against a breach-notification service can also reveal which accounts most urgently need new passwords, turning an abstract warning into a concrete list of changes worth making first.
This article was produced with the assistance of AI and reviewed by Morning Overview editors prior to publication.
More from Morning Overview
- Card skimmers hidden on gas pumps and ATMs are draining accounts, and here’s the tell
- The FBI says hackers are hijacking outdated home routers, and it named the models to check
- Older Teslas are wearing out in ways early owners never saw coming
- A common childhood virus is now tied to multiple sclerosis years later