logo

Public Elasticsearch Servers Expose 9.8 Billion Credential Records Across Enterprise, Cloud, and AI Platforms 

ID: d724629f-8e7b-5044-a5cb-3d413832acdf

STIX ID: report--d724629f-8e7b-5044-a5cb-3d413832acdf

Feed Name: SOCRadar Blog

Threat Score
85/100

Date Published: 2026-04-20

Date Updated: 2026-04-30

Author: Ameer Owda

...
...

SOCRadar discovered three publicly accessible Elasticsearch instances exposing ~9.88 billion credential records (email/password and URL-linked ULP records). Over half of one dataset’s records were corporate emails, and many records mapped to identity providers (Microsoft, Auth0, Okta), cloud and business platforms, and AI services — enabling large-scale credential stuffing, account takeover, and potential infrastructure compromise. Following responsible disclosure the servers were secured.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.