logo

24 Billion Stolen Credentials Exposed in Massive Data Leak

ID: 8f2f580d-5785-5dcf-ad08-362b60652dfe

STIX ID: report--8f2f580d-5785-5dcf-ad08-362b60652dfe

Feed Name: Security Affairs

Threat Score
85/100

Date Published: 2026-06-19

Date Updated: 2026-06-19

Author: Pierluigi Paganini

...
...

Cybernews discovered an exposed Elasticsearch cluster on June 12 containing 24 billion records (8.3 TB) mostly made up of infostealer logs — plaintext usernames, emails, and passwords — aggregated from 36 sources including Telegram channels and large “collections.” The dataset included recent items (one as recent as Feb 2026), CVE references, and signs the owner was actively updating the trove; although the cluster was taken offline after discovery, the sheer scale and content pose a major risk of account takeover for affected users, particularly those without MFA or who reuse passwords.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.