Skip to main content
Breach Signal

Breach report

Credential Compilation

16 billion credential compilation

16 Billion Apple, Facebook, Google And Other Passwords Leaked

Researchers uncovered 30 exposed datasets totaling roughly 16 billion login credentials, much of it harvested by infostealer malware, covering accounts at Apple, Google, Facebook, GitHub, Telegram and government services.

Reported by Forbes

Records exposed

16B

About 16 billion login credentials across 30 datasets

Scale vs. largest on file

When
2025
How they got in
Infostealer malware logs and older breach data aggregated in briefly exposed datasets
Sector
Credential Compilation

On June 18, 2025, researchers at Cybernews published findings that they had discovered 30 datasets, each containing tens of millions to more than 3.5 billion records, adding up to about 16 billion exposed login credentials. The researchers said the datasets had been briefly left open on unsecured Elasticsearch instances and object storage, long enough to be catalogued but not long enough to identify their owners. Cybernews said it had been tracking such exposures since the start of the year and that new datasets were surfacing every few weeks.

Most records followed a structure typical of infostealer malware logs: a website address followed by a username and password. The credentials related to a wide range of services, including Apple, Facebook, Google, GitHub, Telegram, corporate platforms, VPNs and government portals. The largest single dataset, with roughly 3.5 billion records, appeared to be linked to Portuguese-speaking users, and others carried names suggesting links to Russia or to specific malware families. Some entries also included session cookies and tokens that could let attackers bypass passwords.

The story spread rapidly, with headlines describing it as one of the largest breaches ever. Follow-up reporting and security researchers, including BleepingComputer and Forbes, emphasized that it was not a new breach of Apple, Google or Facebook, and that the figure almost certainly included heavy duplication and recycled data from older leaks. Researchers countered that a meaningful portion appeared to be recent infostealer output, which is valuable because it reflects credentials captured directly from infected devices.

No company faced penalties because no single organization was breached, and the owners of the datasets were not identified. Instead, the episode prompted a wave of consumer guidance: check breach notification services, change reused passwords, enable multi-factor authentication and adopt passkeys, which major platforms including Google and Apple had been promoting as phishing-resistant replacements for passwords.

The 16 billion figure became shorthand for the scale of the infostealer economy. Malware that quietly scrapes saved browser passwords from personal and work computers now feeds an enormous underground market, and compilations like these give attackers ready-made lists for account takeover and corporate intrusions. The episode underscored why security teams increasingly monitor for leaked employee credentials and why passwords alone are no longer a sufficient safeguard.

More from the wire

More in Credential Compilation.

All 107 reports

Private AI for Life

Live your best life with Thinkspan: the all-in-one smart solution for organizing, securing, and accessing personal information. With Thinkspan, your life’s most important information stays protected and accessible.