Skip to main content
Breach Signal

Breach report

Credential Compilation

Mother of All Breaches (MOAB)

Warning As 26 Billion Records Leak: Dropbox, LinkedIn, Twitter Named

Researchers found an unsecured 12-terabyte database holding roughly 26 billion records compiled from thousands of past breaches at Tencent, Weibo, MySpace, Twitter, LinkedIn and others, dubbing it the Mother of All Breaches.

Reported by Forbes

Records exposed

26B

About 26 billion records

Scale vs. largest on file

When
2024
How they got in
Misconfigured open storage instance holding an aggregated breach compilation
Sector
Credential Compilation

In January 2024, researchers from Cybernews and Security Discovery, including Bob Diachenko, reported finding an exposed storage instance containing about 12 terabytes of data and roughly 26 billion records. They nicknamed it the Mother of All Breaches, or MOAB, because of its unprecedented size. The data was organized into about 3,800 folders, each apparently corresponding to a separate earlier breach.

The largest contributors were Chinese messaging service Tencent QQ, with about 1.5 billion records, and Weibo, with roughly 504 million. Other large sets were attributed to MySpace, Twitter, Deezer, LinkedIn, Adobe, Canva, Dropbox and Telegram, as well as government organizations in the United States, Brazil, Germany and other countries. The researchers said the trove appeared to be a compilation built by a data broker or someone reselling stolen information, rather than the product of a single new hack.

Because most of the contents came from breaches that were already known, many security experts cautioned against treating MOAB as a fresh compromise of the companies named. Still, the researchers noted that the compilation likely contained some previously unreported data and that aggregating records in one place makes it easier to cross-reference identities, link email addresses to phone numbers and passwords, and build profiles for phishing and account takeover.

The owner of the storage instance was never publicly identified, and no enforcement action followed. The discovery was widely covered because it provided a stark measure of how much personal data from past incidents continues to circulate. Security firms and news outlets urged people to check whether their accounts appeared in breach notification services and to change reused passwords. Cybernews built a search tool so people could check whether their details appeared, and the story circulated widely on social media and television news. Its sheer size made it a frequent reference point in later coverage of credential leaks.

MOAB illustrates a key dynamic of the breach economy: old leaks never truly disappear. Criminals continually merge, deduplicate and repackage datasets, and each compilation extends the useful life of stolen credentials. The practical defenses remain unchanged, including unique passwords stored in a password manager, multi-factor authentication and, increasingly, passkeys that cannot be reused across sites.

More from the wire

More in Credential Compilation.

All 107 reports

Private AI for Life

Live your best life with Thinkspan: the all-in-one smart solution for organizing, securing, and accessing personal information. With Thinkspan, your life’s most important information stays protected and accessible.