Breach report
Credential CompilationMother of All Breaches (MOAB)
Warning As 26 Billion Records Leak: Dropbox, LinkedIn, Twitter Named
Researchers found an unsecured 12-terabyte database holding roughly 26 billion records compiled from thousands of past breaches at Tencent, Weibo, MySpace, Twitter, LinkedIn and others, dubbing it the Mother of All Breaches.
Reported by Forbes
Records exposed
26B
About 26 billion records
Scale vs. largest on file
- When
- 2024
- How they got in
- Misconfigured open storage instance holding an aggregated breach compilation
- Sector
- Credential Compilation
In January 2024, researchers from Cybernews and Security Discovery, including Bob Diachenko, reported finding an exposed storage instance containing about 12 terabytes of data and roughly 26 billion records. They nicknamed it the Mother of All Breaches, or MOAB, because of its unprecedented size. The data was organized into about 3,800 folders, each apparently corresponding to a separate earlier breach.
The largest contributors were Chinese messaging service Tencent QQ, with about 1.5 billion records, and Weibo, with roughly 504 million. Other large sets were attributed to MySpace, Twitter, Deezer, LinkedIn, Adobe, Canva, Dropbox and Telegram, as well as government organizations in the United States, Brazil, Germany and other countries. The researchers said the trove appeared to be a compilation built by a data broker or someone reselling stolen information, rather than the product of a single new hack.
Because most of the contents came from breaches that were already known, many security experts cautioned against treating MOAB as a fresh compromise of the companies named. Still, the researchers noted that the compilation likely contained some previously unreported data and that aggregating records in one place makes it easier to cross-reference identities, link email addresses to phone numbers and passwords, and build profiles for phishing and account takeover.
The owner of the storage instance was never publicly identified, and no enforcement action followed. The discovery was widely covered because it provided a stark measure of how much personal data from past incidents continues to circulate. Security firms and news outlets urged people to check whether their accounts appeared in breach notification services and to change reused passwords. Cybernews built a search tool so people could check whether their details appeared, and the story circulated widely on social media and television news. Its sheer size made it a frequent reference point in later coverage of credential leaks.
MOAB illustrates a key dynamic of the breach economy: old leaks never truly disappear. Criminals continually merge, deduplicate and repackage datasets, and each compilation extends the useful life of stolen credentials. The practical defenses remain unchanged, including unique passwords stored in a password manager, multi-factor authentication and, increasingly, passkeys that cannot be reused across sites.