Morning Overview

Researchers found 24 billion stolen usernames and passwords sitting exposed online

Anyone who reuses the same password across multiple websites now faces a sharply higher risk of account takeover. A threat-intelligence study by Digital Shadows documented 24 billion stolen username-and-password pairs circulating on dark web marketplaces and criminal forums, a 65 percent increase over a two-year span. Even after removing duplicates, the dataset still contained 6.7 billion unique credential sets, each one a potential key to someone’s email, bank account, or employer network.

Why 24 billion exposed credentials change the threat calculus

The sheer volume of stolen login data now available to attackers has shifted the economics of cybercrime. Credential-stuffing attacks, where automated tools try leaked passwords against dozens of services at once, become far more effective when the pool of raw material grows by 65 percent. A criminal who purchases or downloads even a fraction of the 24 billion records documented by Digital Shadows research can target millions of accounts with minimal effort or skill.

One hypothesis worth testing is whether this surge stems mainly from the rapid spread of commodity infostealer malware on consumer devices rather than from a spike in large-scale corporate breaches. Infostealers such as RedLine, Raccoon, and Vidar harvest credentials directly from browsers and password managers on individual machines. Each infected device can yield dozens of login pairs, and the malware is sold cheaply on underground forums, lowering the barrier for entry-level criminals. If infostealers are the primary engine behind the growth, the pattern would explain why the total credential count ballooned so quickly without a corresponding wave of headline-grabbing corporate intrusions.

The Digital Shadows data does not break out the share of credentials attributable to infostealers versus traditional database breaches. That gap in the reporting leaves the hypothesis plausible but unconfirmed. What the numbers do confirm is that the problem is accelerating: the jump from roughly 15 billion records two years earlier to 24 billion signals that credential theft is scaling faster than most organizations or individuals are adapting their defenses.

From an attacker’s perspective, the landscape looks increasingly favorable. Automated tools can ingest massive credential dumps, test them across hundreds of services, and flag successful logins for later exploitation or resale. The cost of running these operations continues to fall, while the potential payoff – access to financial accounts, internal corporate systems, or high-value email inboxes – remains high. The imbalance between low-cost attacks and high-value targets is exactly what fuels the growth of underground credential markets.

What the Digital Shadows dataset reveals after deduplication

Raw counts can be misleading because the same stolen pair often appears in multiple breach compilations, paste sites, and resale listings. Digital Shadows addressed this by deduplicating the full 24 billion records and arriving at 6.7 billion unique credentials. That figure represents distinct combinations of a username or email address paired with a password, each one tied to at least one real account somewhere on the internet.

The ratio between raw and deduplicated totals, roughly 3.6 duplicates per unique pair, itself tells a story. Widespread password reuse means the same credential works on multiple services, so criminals recirculate it across forums and compilation files. Every time a user sets the same password on a shopping site, a streaming service, and a corporate VPN, one stolen record effectively becomes three attack opportunities.

The 65 percent growth rate also suggests that fresh credentials are entering the underground market faster than old ones are being invalidated by password resets or account closures. Organizations that rely on periodic password rotation as their primary defense are losing ground to the pace of new theft. The gap between the speed of compromise and the speed of remediation is widening, not shrinking.

Another implication of the deduplication results is that traditional breach-notification practices, which focus on individual incidents, may understate the cumulative exposure of any given user. Someone whose email address appears in multiple breaches might receive several separate alerts over the years, but attackers see a consolidated view: a long history of reused passwords and associated services. The Digital Shadows dataset, by aggregating and cleaning these records, approximates that attacker’s-eye perspective more closely than isolated breach disclosures do.

Gaps in the evidence and what to watch next

Several questions remain open. Digital Shadows has not published the full methodology behind its collection and deduplication process. Without knowing how the firm scanned dark web markets, which forums it monitored, or how it validated that credentials were still active, outside researchers cannot independently reproduce the 24 billion figure or the 6.7 billion unique count. The study was distributed through a press announcement on a newswire platform, not a peer-reviewed journal, so it has not undergone formal academic scrutiny.

No affected organizations or breach victims have publicly corroborated the report’s scale. Large-scale breach disclosures from companies such as LinkedIn, Yahoo, and Facebook over the past decade account for billions of records on their own, but mapping specific corporate incidents to the Digital Shadows total is not possible with the information available. The report also does not specify what share of the 24 billion records come from breaches older than five years versus recent theft, a distinction that matters because older credentials are more likely to have been changed.

The absence of a breakdown by source type, whether corporate breach, phishing campaign, or infostealer harvest, limits the ability of security teams to prioritize their defenses. If most new credentials are arriving through infostealers, then endpoint protection and browser-based password hygiene matter more than perimeter security. If large-scale database dumps are still the dominant contributor, then organizations need to invest more heavily in breach detection and rapid credential invalidation.

Future research that clarifies the age distribution of stolen credentials, their origin, and their success rates in real-world attacks would help security leaders calibrate their investments. For example, knowing whether a majority of successful account takeovers rely on credentials stolen within the last 12 months versus older data would influence how aggressively companies enforce password resets after a breach alert.

What organizations and individuals should do now

For individual users, the practical takeaway is direct. Anyone still relying on a single password across multiple accounts should treat the 24 billion figure as a clear signal to act. Enabling multi-factor authentication on every service that supports it is the single most effective step, because it renders a stolen password alone insufficient for access. Using a password manager to generate and store unique, complex passwords for each site sharply reduces the damage a single breach can cause.

Organizations, meanwhile, need to assume that at least some employee credentials are already circulating in underground markets. That assumption should drive the adoption of layered defenses: enforcing strong, unique passwords; mandating multi-factor authentication, especially for remote access and administrative accounts; monitoring for suspicious login patterns indicative of credential-stuffing; and integrating threat-intelligence feeds that flag when corporate email domains appear in new dumps.

The Digital Shadows figures are striking, but they do not mark a sudden turning point so much as the continuation of a long-running trend toward industrialized credential theft. The core defensive principles – minimizing reuse, adding additional verification factors, and rapidly invalidating exposed passwords – remain the same. What has changed is the scale and speed at which attackers can exploit any lapse in those practices.

In that sense, the 24 billion exposed credentials are less a shocking revelation than a quantitative reminder that passwords, on their own, are a brittle foundation for digital identity. Until more services adopt stronger, phishing-resistant authentication methods, both users and organizations will have to operate under the assumption that passwords are already in the wrong hands – and design their defenses accordingly.

More from Morning Overview

*This article was researched with the help of AI, with human editors creating the final content.