Home
Finance
Travel
Shopping
Academic
Library
Create a Thread
Home
Discover
Spaces
 
 
  • Fresh Data Creates New Threat
  • Scale Dwarfs Previous Incidents
16 billion stolen passwords discovered in massive breach

Security researchers have uncovered what appears to be one of the largest collections of stolen login credentials in history, exposing more than 16 billion usernames and passwords from major technology platforms including Apple, Google, and Facebook. The discovery, reported today by Cybernews, represents fresh data collected through malware rather than recycled information from previous breaches.

The breach provides cybercriminals with what researchers call "unprecedented access to personal credentials that can be used for account takeover, identity theft, and highly targeted phishing".

User avatar
Curated by
feylune
2 min read
Published
18,315
2,479
news.trendmicro.com favicon
Trend Micro News
Data Breach 2025: Meta, Coinbase, AT&T, Google, Apple, M&S, and ...
cybernews.com favicon
Cybernews
The 16-billion-record data breach that no one’s ever heard of
cryptopolitan.com favicon
Cryptopolitan
Largest data breach ever: 16 billion Apple, Facebook, Google passwords leaked
16 billion logins discovered across exposed datasets
appleinsider.com
Fresh Data Creates New Threat

The Cybernews research team identified 30 separate datasets containing between tens of millions and 3.5 billion records each, discovered since monitoring began in January12. Unlike previous major breaches that often recycle old information, only one dataset—containing 184 million records reported by Wired magazine in May—had been publicly disclosed before13.

"This is not just a leak – it's a blueprint for mass exploitation," researchers told Cybernews1. The credentials provide access to platforms ranging from social media and corporate systems to VPN services and government portals42.

The data appears structured for automated attacks, with uniform formatting showing platform URLs followed by usernames and passwords4. Researchers linked the breach to infostealer malware, which silently harvests credentials from infected devices along with session tokens, cookies, and metadata15.

cybernews.com favicon
digitalinformationworld.com favicon
news.trendmicro.com favicon
5 sources
Scale Dwarfs Previous Incidents

The discovery surpasses recent major breaches in scope and recency. Last year's RockYou2024 compilation exposed 9.9 billion passwords, though that collection primarily contained previously leaked data12. Earlier this year, researchers identified the "Mother of All Breaches" containing 26 billion records, but that dataset was largely composed of older, recycled information3.

The fresh nature of the current breach poses particular risks for cryptocurrency users, as attackers could exploit cloud-stored recovery phrases or target custodial wallet services45. Tom's Guide reports that the structured data could enable "credential stuffing" attacks, where automated tools test stolen login combinations across multiple websites6.

Companies affected have not yet issued official statements4. Snapchat previously stated it found no evidence of direct system breaches when the smaller May dataset emerged, supporting theories that the data was harvested from individual users rather than corporate servers7.

"What's especially concerning is the structure and recency of these datasets – these aren't just old breaches being recycled. This is fresh, weaponizable intelligence at scale," the Cybernews team said6.

thecyberexpress.com favicon
mcafee.com favicon
omnicybersecurity.com favicon
7 sources
Related
How can I protect my accounts from this massive credential leak
What steps should I take if I suspect my credentials were stolen
Why are infostealer malware attacks increasing in frequency and scale
Discover more
ServiceNow patches high-severity flaw affecting Fortune 500s
ServiceNow patches high-severity flaw affecting Fortune 500s
ServiceNow issued a CVE designation on July 8 for a high-severity vulnerability that security researchers say could have exposed sensitive data across hundreds of tables in the widely-used enterprise platform. The flaw, dubbed "Count(er) Strike" by Varonis researchers who discovered it, exploits weaknesses in ServiceNow's access control logic to allow low-privileged users to extract restricted...
20
German court orders Meta to pay €5,000 for privacy breach
German court orders Meta to pay €5,000 for privacy breach
A German court has ordered Meta to pay €5,000 to a Facebook user in a ruling that found the social media giant's tracking technology embedded across millions of websites violates European privacy laws. The Leipzig Regional Court delivered its judgment on July 4, finding that Meta's tracking pixels and software development kits collect user data without consent, breaching the General Data...
64
Adobe patches 58 vulnerabilities, 3 critical flaws
Adobe patches 58 vulnerabilities, 3 critical flaws
Adobe released security patches on Tuesday for 58 vulnerabilities across 13 products, including three critical flaws that could allow hackers to execute malicious code on users' computers. The most severe vulnerability, tracked as CVE-2025-27203, affects Adobe Connect and carries a CVSS severity score of 9.3 out of 10. The patches address a wave of code execution bugs that security experts warn...
113
Brother printer flaw affects millions, can't be patched
Brother printer flaw affects millions, can't be patched
Security researchers have discovered a critical vulnerability affecting hundreds of Brother printer models that cannot be fixed through software updates, leaving millions of devices potentially exposed to remote attacks. The flaw, disclosed June 25 by cybersecurity firm Rapid7, allows attackers to generate default administrator passwords for 689 Brother printer, scanner and label maker models,...
23,262