Open padlock on a bunch of keys showing credentials leak

Massive Credentials Leak Exposed the Login Information of Over 149 Million Accounts

A massive credentials leak has exposed more than 149 million login usernames and passwords after a threat actor failed to secure a database storing the stolen data.

Renowned cybersecurity researcher Jeremiah Fowler stumbled upon the trove, totaling about 96 GB, believed to have been harvested using an infostealer malware.

Massive credentials leak affects 149 million accounts

The comprehensive credentials leak included emails, usernames, passwords, and links to websites to which they were used to log in. They included Gmail, Facebook, Netflix, Instagram, TikTok, Binance, iCloud, OnlyFans, .edu domains, and government websites, among others.

“Exposed government credentials could be potentially used for targeted spear-phishing, impersonation, or as an entry point into government networks,” Fowler explained.

The credentials leak also affected financial services, trading accounts, cryptocurrency wallets, credit cards, and banking account logins.

According to the security researcher, the database was unsecured, and the credentials were unencrypted, leaving them accessible to anyone with a web browser who knew where to look.

“The publicly exposed database was not password-protected or encrypted,” he told ExpressVPN. “The database was publicly accessible, allowing anyone who discovered it to potentially access the credentials of millions of individuals.”

Additionally, the list continued to grow as Fowler attempted to take the database offline, suggesting the process was highly automated, typical of infostealer malware.

“One disturbing fact is that the number of records increased from the time I discovered the database until it was restricted and no longer available,” Fowler said.

With no identifying information for the database owner, the cybersecurity researcher contacted the hosting provider to secure the database. He expressed his frustrations while attempting to shut down the threat actor’s domain.

“I received a reply several days later stating that they do not host the IP and it is a subsidiary that operates independently while still using the parent organization’s name,” Fowler said. “It took nearly a month and multiple attempts before action was finally taken and the hosting was suspended and millions of stolen login credentials were no longer accessible.”

Ultimately, the hosting provider refused to disclose any identifying information about the entity managing the unsecured database.

“This reported dataset matters less because of its size and more because of what it represents operationally,” said Shane Barney, Chief Information Security Officer at Keeper Security. “This is not a breach in the traditional sense, and it is not evidence of a single failure. It is the byproduct of an ecosystem that continuously harvests credentials from endpoints and quietly accumulates access over time.”

Credentials leak puts millions at risk of account takeovers

In addition to account takeover via direct login to compromised accounts and credential stuffing, attackers could use the stolen information for phishing attacks. Individuals who reuse passwords across various services could have multiple accounts compromised as a result of the credentials leak.

“The data is a gold mine for cybercriminals launching credential stuffing attacks. Cybercriminals can use stolen username and password combinations to log into a wide array of accounts under the assumption that many people use the same password across multiple accounts. This process is automated, so a hacker can attempt to use a single set of credentials across dozens or even hundreds of accounts in a matter of seconds,” explained Paul Bischoff, Consumer Privacy Advocate at Comparitech.

“Once login and password pairs are exposed, even from criminal infrastructure, they become fuel for credential stuffing: automated attempts to reuse those same credentials across other applications and services. Given how common password reuse is, this creates a persistent and highly scalable threat,” added Mayur Upadhyaya, CEO at APIContext.

Attackers could also log into government websites and access identifying personal information, including ID numbers, driver’s licenses, and Social Security Numbers. If administrator credentials leaked, attackers could also target government systems and disrupt essential services or even deploy ransomware.

As a precaution, users should enable multifactor authentication to prevent threat actors from logging into their accounts if their credentials leak.

“Authentication best practices always recommend: unique passwords for every site, never reusing passwords, enabling MFA or at least 2FA for website (and avoiding 1FA whenever possible), using a monitoring service like LegalShield, LifeLock, etc. or even the built in password security detection built into Apple IOS to determine if credentials are exposed on the dark web so users can change their passwords – and lastly, never accepting 2FA/MFA notifications unless you have initiated them,” said Morey Haber, Chief Security Advisor at BeyondTrust.

Meanwhile, Fowler explained that the massive credentials leak is hardly the first he has encountered, highlighting the threat posed by infostealers.

“This is not the first dataset of this kind I have discovered and it only highlights the global threat posed by credential-stealing malware,” he stated.

He also emphasized that the credentials leak signaled that no one, including cybercriminals, is immune to data breaches.

“When data is collected, stolen, or harvested it must be stored somewhere and a cloud based repository is usually the best solution. This discovery also shows that even cybercriminals are not immune to data breaches.”